An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)
Process hollowing replaces the legitimate image with malicious code, so the in-memory image no longer matches the on-disk executable. Detecting a primary image region that is unbacked or whose contents differ from the file at the recorded path is a core indicator. This artifact alone is highly suggestive when combined with other anomalies.
Why this answer
Process hollowing unmaps or overwrites the original image and injects replacement code, so the primary image region loses its legitimate file backing and threads often start in unbacked memory. Observing both an unbacked primary image and a thread starting outside known modules forms a coherent, high-confidence pattern. Pipe handles, token privilege changes, and working set size are unrelated to the hollowing technique.
Exam trap
The trap here is treating any single anomaly as proof of hollowing, when the technique is best confirmed by combining image-backing and thread-start anomalies.