GCFA Enterprise Environment Incident Response Practice Question
An incident responder is investigating a compromised Windows system and finds that the attacker used a technique known as 'process hollowing' to hide malicious code. Which of the following best describes how process hollowing works?
⚠ Common exam trap
Many candidates confuse process hollowing with other code injection techniques like remote thread injection or DLL injection, which do not involve replacing the entire process image.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker creates a new process in a suspended state, replaces its memory with malicious code, and then resumes the process.
Process hollowing is a technique where an attacker creates a legitimate process in a suspended state, replaces its memory with malicious code, and then resumes it. This allows the malicious code to run under the guise of a trusted process, making it harder to detect. Memory forensics can reveal inconsistencies between the on-disk executable and the in-memory image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The attacker injects malicious code into a running process by using remote thread creation, without replacing the entire process image.
Why it's wrong here
This describes remote thread injection or DLL injection, not process hollowing. In process hollowing, the original process image is replaced entirely. While both are code injection techniques, process hollowing specifically involves creating a suspended process and hollowing out its memory. This option is a common confusion between similar techniques. The responder should distinguish between them based on memory artifacts.
- ✗
The attacker exploits a vulnerability in a legitimate process to execute arbitrary code within its context, without modifying its memory.
Why it's wrong here
This describes exploitation of a vulnerability, which may lead to code execution but not necessarily process hollowing. Process hollowing involves deliberately replacing the process's memory. Exploitation may be a precursor, but the technique itself is different. This option is too broad and does not capture the specific memory manipulation of hollowing. The responder should look for signs of memory replacement.
- ✓
The attacker creates a new process in a suspended state, replaces its memory with malicious code, and then resumes the process.
Why this is correct
Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, writing malicious code into the address space, and then resuming the process. This makes the malicious code appear to run under a legitimate process name, evading detection. The responder should look for discrepancies between the process's image on disk and its in-memory content, often using memory forensics tools like Volatility.
- ✗
The attacker uses a scheduled task to execute a malicious script that masquerades as a legitimate system process.
Why it's wrong here
This describes masquerading or scheduled task abuse, not process hollowing. Process hollowing is a memory manipulation technique where a legitimate process's memory is replaced with malicious code. Scheduled tasks are a persistence mechanism. This option conflates different attacker techniques. The responder should focus on memory analysis to detect hollowing.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.