CAS-004 Security Operations Practice Question
During an incident response, a forensic analyst captures the memory of a compromised Windows system. Using Volatility, the analyst runs the 'pslist' command and sees a suspicious process 'svchost.exe' with a parent process 'explorer.exe'. Which Volatility plugin should the analyst use next to detect potential process hollowing?
⚠ Common exam trap
The trap is picking a plugin that sounds memory-related (psxview, dlllist) but actually serves a different purpose — only malfind scans for injected/hollowed executable memory regions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
malfind
The malfind plugin is specifically designed to detect injected code and process hollowing by scanning process memory for regions with suspicious characteristics such as PAGE_EXECUTE_READWRITE permissions and MZ/PE headers in non-image memory. Given the suspicious svchost.exe parented by explorer.exe (svchost should normally be parented by services.exe), malfind is the correct next step to confirm hollowing or injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
netscan
Why it's wrong here
netscan enumerates network endpoints and connections from memory, which is unrelated to detecting hollowed process images. It is the correct plugin when correlating a suspicious process with listening ports or outbound connections, not for comparing in-memory image sections against the on-disk executable.
- ✗
psxview
Why it's wrong here
psxview cross-references multiple process-listing sources to expose hidden or unlinked processes, but it does not inspect in-memory image sections for hollowing. It is tempting because it detects process concealment, which is the correct choice when rootkits hide entries from pslist rather than when a legitimate parent spawns a replaced image.
- ✗
dlllist
Why it's wrong here
dlllist lists loaded modules per process, useful for spotting unexpected DLLs, but hollowing replaces the process image itself, leaving module lists largely intact. It is the right plugin for investigating DLL injection or side-loading, whereas hollowing is confirmed by comparing mapped image sections with the file on disk.
- ✓
malfind
Why this is correct
malfind scans process memory for injected code by locating regions with executable permissions lacking a mapped file on disk, the hallmark of process hollowing. Given the suspicious svchost.exe parented by explorer.exe, it directly tests the injected-code hypothesis pslist cannot confirm.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.