GCIH Endpoint Attack and Pivoting Practice Question
During an incident response on a Windows 10 endpoint, you observe that a malicious process has injected a thread into a remote process on the same host using the CreateRemoteThread API. The injected code is now executing in the context of a legitimate system process. Which of the following best describes the primary purpose of this technique from the attacker's perspective?
⚠ Common exam trap
The trap here is assuming that any process injection automatically leads to privilege escalation, when in fact the primary goal is often stealth and defense evasion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To evade detection by masquerading malicious code within a trusted process.
Injecting a thread into a remote process using CreateRemoteThread enables an adversary to execute arbitrary code within the address space of a trusted process. This helps evade detection because many security solutions allowlist or trust system processes. The technique does not inherently escalate privileges, create network tunnels, or dump credentials, making the evasion-focused description the correct one.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To harvest credentials from the LSASS process memory.
Why it's wrong here
Credential dumping from LSASS typically involves reading its memory, often via tools like Mimikatz, but that is a distinct activity from injecting a remote thread. The scenario states the injected code is executing in a legitimate process, not extracting credentials. This option misattributes the technique's objective.
- ✓
To evade detection by masquerading malicious code within a trusted process.
Why this is correct
CreateRemoteThread injection allows an attacker to run code inside a legitimate process, such as explorer.exe or svchost.exe. Security tools often trust these processes, so the malicious activity may blend in with normal behavior. This provides stealth and persistence, making it the primary purpose in the given scenario.
- ✗
To establish a covert channel over DNS for command and control.
Why it's wrong here
DNS tunneling is a network-based exfiltration and C2 technique, not a process injection method. The CreateRemoteThread API operates locally within a host and does not create network channels by itself. This option confuses a host-based evasion technique with a network covert channel.
- ✗
To escalate privileges by exploiting a vulnerable driver in the kernel.
Why it's wrong here
Kernel driver exploitation is a separate privilege escalation technique that targets vulnerabilities in signed drivers, not process injection via CreateRemoteThread. The scenario describes user-mode code injection into another process, which does not inherently involve kernel components. This option misidentifies the mechanism and its goal.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.