CS0-003 Security Operations Practice Question
An analyst is reviewing a memory dump of a compromised system and notices that the memory of a legitimate process (e.g., notepad.exe) contains a PE header and executable code that is not part of the original binary. Which technique is most likely being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process hollowing
Process hollowing involves replacing the legitimate code of a running process with malicious code, but the PE header and executable code in memory indicate code injection, specifically hollowing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A reflective DLL loader
Why it's wrong here
A reflective DLL loader maps and executes a DLL entirely from memory without touching disk, but it operates as an additional loaded module within a process rather than overwriting the host process's own executable image, so it would not produce a foreign PE header replacing the original binary's code as described.
- ✓
Process hollowing
Why this is correct
Process hollowing launches a legitimate process in a suspended state, unmaps its original executable image from memory, and writes malicious code and a new PE header into that same memory space before resuming execution, which is exactly why memory forensics reveals a legitimate process name like notepad.exe containing a PE header and code that does not match its original binary on disk.
- ✗
DLL injection
Why it's wrong here
DLL injection forces a target process to load and execute an additional malicious DLL module alongside its existing, unmodified code, so the process's original executable image and PE header remain intact; it introduces new loaded modules rather than replacing the process's own binary content.
- ✗
API hooking
Why it's wrong here
API hooking intercepts and redirects specific function calls, typically by patching a jump instruction into an API's entry point, to alter behavior of individual calls; it does not replace the process's core executable image or introduce a foreign PE header, which rules it out as the source of the observed artifact.
Go deeper
Related to this question
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.