Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

During an incident response on a Windows 10 endpoint, you observe that a malicious process has injected a thread into a remote process on the same host using the CreateRemoteThread API. The injected code is now executing in the context of a legitimate system process. Which of the following best describes the primary purpose of this technique from the attacker's perspective?

⚠ Common exam trap

The trap here is assuming that any process injection automatically leads to privilege escalation, when in fact the primary goal is often stealth and defense evasion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To evade detection by masquerading malicious code within a trusted process.

Injecting a thread into a remote process using CreateRemoteThread enables an adversary to execute arbitrary code within the address space of a trusted process. This helps evade detection because many security solutions allowlist or trust system processes. The technique does not inherently escalate privileges, create network tunnels, or dump credentials, making the evasion-focused description the correct one.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To harvest credentials from the LSASS process memory.

    Why it's wrong here

    Credential dumping from LSASS typically involves reading its memory, often via tools like Mimikatz, but that is a distinct activity from injecting a remote thread. The scenario states the injected code is executing in a legitimate process, not extracting credentials. This option misattributes the technique's objective.

  • ✓

    To evade detection by masquerading malicious code within a trusted process.

    Why this is correct

    CreateRemoteThread injection allows an attacker to run code inside a legitimate process, such as explorer.exe or svchost.exe. Security tools often trust these processes, so the malicious activity may blend in with normal behavior. This provides stealth and persistence, making it the primary purpose in the given scenario.

  • ✗

    To establish a covert channel over DNS for command and control.

    Why it's wrong here

    DNS tunneling is a network-based exfiltration and C2 technique, not a process injection method. The CreateRemoteThread API operates locally within a host and does not create network channels by itself. This option confuses a host-based evasion technique with a network covert channel.

  • ✗

    To escalate privileges by exploiting a vulnerable driver in the kernel.

    Why it's wrong here

    Kernel driver exploitation is a separate privilege escalation technique that targets vulnerabilities in signed drivers, not process injection via CreateRemoteThread. The scenario describes user-mode code injection into another process, which does not inherently involve kernel components. This option misidentifies the mechanism and its goal.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.