CS0-003 Security Operations Practice Question
An analyst suspects a process hollowing attack on an endpoint. Which of the following EDR telemetry findings would best support this hypothesis?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A legitimate process (e.g., svchost.exe) created in a suspended state and later resumed with changed memory contents
Process hollowing involves creating a legitimate process in a suspended state, then replacing its memory with malicious code. This leaves the original path unchanged but the process may exhibit unusual child process behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A legitimate process (e.g., svchost.exe) created in a suspended state and later resumed with changed memory contents
Why this is correct
Process hollowing specifically involves spawning a legitimate system process (like svchost.exe) in a suspended state using the CREATE_SUSPENDED flag, unmapping its original executable code from memory, writing a malicious payload into that hollowed space, and then resuming the thread. This allows the malware to masquerade as a trusted process while executing arbitrary code under its identity.
- ✗
A process with the same name as a Windows system process but running from a temporary directory
Why it's wrong here
Running a binary with a system name from an unusual directory like a temporary folder is a classic indicator of path-based masquerading or name spoofing. While highly suspicious and indicative of malware execution, it does not involve the runtime memory manipulation and process replacement techniques that define true process hollowing.
- ✗
A process injecting code into a legitimate running process
Why it's wrong here
This describes classic DLL injection or basic process injection, where an active, running target process is forced to host malicious code via APIs like VirtualAllocEx and WriteProcessMemory. Unlike process hollowing, this technique does not create a new suspended process to completely replace its primary executable image before execution begins.
- ✗
An unknown process making network connections to multiple internal IPs
Why it's wrong here
An unrecognized process initiating multiple internal network connections is a strong indicator of internal reconnaissance, port scanning, or lateral movement. While this behavior is highly malicious and requires immediate containment, it represents network-level activity rather than the host-level memory tampering characteristic of process hollowing.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Telemetry
Telemetry is the automatic collection, transmission, and measurement of data from remote sources to a central system for analysis and monitoring.
Key term
EDR
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices to detect, investigate, and respond to advanced threats.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.