Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating a potential memory injection attack on a Windows system. Which of the following memory analysis artifacts is most indicative of code injection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A process with a memory region that is both writable and executable (RWX)

A process that is executing in a region of memory that is both writable and executable (RWX) is a strong indicator of injected code, as legitimate processes typically have separate write and execute permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A process with a memory region that is both writable and executable (RWX)

    Why this is correct

    Memory injection techniques, such as process hollowing or DLL injection, require allocating memory with write permissions to copy payload code, and then execute permissions to run it. Legitimate software rarely allocates memory regions with concurrent Read-Write-Execute (RWX) permissions due to security mitigations like Data Execution Prevention (DEP) or W^X (Write XOR Execute). Finding an RWX memory region strongly indicates that shellcode has been injected and is prepared for execution.

  • ✗

    A process that is running from a temp directory

    Why it's wrong here

    While executing binaries from temporary directories (like %TEMP% or /tmp) is a common indicator of compromise (IoC) associated with initial access or dropper execution, it does not directly indicate memory injection. Legitimate installers and self-extracting archives frequently run from these directories. Memory injection specifically involves manipulating the virtual memory space of a running process, regardless of the initial binary's disk location.

  • ✗

    A process that has an unusually high handle count

    Why it's wrong here

    An elevated handle count typically points to a resource leak within an application, where system resources like files, registry keys, or threads are opened but not properly closed. While an attacker might open handles to target processes during an injection attempt, a high handle count on its own is a generic performance anomaly rather than a definitive indicator of memory injection.

  • ✗

    A process with multiple threads in a suspended state

    Why it's wrong here

    Although some injection techniques, such as process hollowing, temporarily suspend a target process's primary thread to replace its code, suspended threads are common in normal operating system behavior. Legitimate applications frequently suspend threads during debugging, synchronization, or resource management. Therefore, the mere presence of suspended threads is too non-specific to serve as a reliable indicator of an active memory injection attack.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.