CHFI Malware Forensics Practice Question
A forensic analyst is investigating a malware incident on a Windows system and suspects that the malware uses process injection to execute malicious code within a legitimate process. The analyst has acquired a memory dump of the system. Which two of the following techniques should the analyst use to detect and analyze process injection? (Choose two.)
⚠ Common exam trap
The trap here is relying on signature-based scanning or network logs, which do not directly reveal process injection in memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Volatility command malfind to identify hidden or injected code in process memory.
Detecting process injection from a memory dump requires techniques that directly examine process memory. Comparing on-disk and in-memory executable sections reveals modifications, while the Volatility malfind plugin scans for suspicious memory regions indicative of injected code. These two methods are specifically designed to uncover injection artifacts and are standard in memory forensics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analyze network traffic captures for signs of data exfiltration from the injected process.
Why it's wrong here
While network traffic analysis can reveal malicious communication, it does not directly detect process injection. The question asks for techniques to detect and analyze process injection from a memory dump. Network captures are separate from memory analysis and would not show the injection itself. Thus, this technique is not suitable for the specific requirement.
- ✗
Check the Windows event logs for process creation events with unusual parent-child relationships.
Why it's wrong here
Event logs can indicate suspicious process behavior, but they do not directly detect process injection from a memory dump. Process injection often occurs within an existing process, so it may not generate new process creation events. While parent-child anomalies can hint at malicious activity, they are not specific to injection and are not derived from memory analysis.
- ✓
Use the Volatility command malfind to identify hidden or injected code in process memory.
Why this is correct
The Volatility plugin malfind is designed to detect hidden or injected code in process memory by scanning for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk. It is a standard tool for memory forensics and can reveal injected code from techniques like process hollowing or DLL injection. This directly addresses the scenario.
- ✗
Run a full antivirus scan on the memory dump file to detect known malware signatures.
Why it's wrong here
Antivirus scanning of a memory dump is not a reliable method for detecting process injection because it relies on signatures that may not be present in memory or may be obfuscated. Moreover, antivirus tools are not designed to interpret memory dumps and may miss injected code that is not recognized as malicious. This approach is ineffective for the specific task of identifying process injection artifacts.
- ✓
Examine the memory dump for discrepancies between the executable sections on disk and those in memory.
Why this is correct
Process injection often involves injecting code into the memory space of a legitimate process, causing the in-memory executable sections to differ from the on-disk version. By comparing the disk image of the executable with its memory-resident image, an analyst can identify injected code or modifications. This technique is effective for detecting classic injection methods like reflective DLL injection or shellcode injection.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
RAM Analysis
RAM Analysis is the forensic examination of a computer’s volatile memory to uncover evidence of running processes, network connections, malware, and user activity that is lost when the system is powered off.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.