GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?
⚠ Common exam trap
Candidates often focus solely on the process name, ignoring the parent-child relationship, which allows attackers to hide malicious activity by masquerading as legitimate processes like 'svchost.exe' or 'explorer.exe'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To detect anomalies in process lineage and execution context.
PPID analysis reveals the execution chain, which is often a major red flag for malicious activity. For example, a web server process spawning a shell is highly suspicious. Understanding these relationships allows incident handlers to detect process hollowing and injection attacks. This context is essential because it distinguishes between legitimate system operations and adversarial techniques designed to blend into the system's normal process hierarchy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To identify which user account initiated the malicious activity.
Why it's wrong here
The PPID identifies the process that spawned another process, not the user account that initiated the execution. While this information is useful, it is not the primary purpose of PPID analysis, which is to verify the legitimacy of the process lineage and detect suspicious parent-child relationships in process trees.
- ✓
To detect anomalies in process lineage and execution context.
Why this is correct
Analyzing the parent process is essential to determine if a process was spawned by an expected entity. Anomalous process lineages, such as a browser spawning a command shell, are strong indicators of exploitation. This context helps differentiate between normal system operations and malicious activity, enabling effective incident detection and root-cause analysis.
- ✗
To determine the file creation date on the disk.
Why it's wrong here
The PPID describes the relationship between active processes in memory, not file system metadata. File creation dates are stored in the MFT or file system journals. Relying on PPID for file attribution is technically incorrect and would fail to provide the historical context required for accurate timeline analysis of an incident.
- ✗
To ensure the process is running with administrative privileges.
Why it's wrong here
A process's privilege level is defined by its access token and SID, not by the identity of its parent. While a parent might pass certain attributes to a child, the PPID itself does not dictate or report the privilege level. Incident handlers must check specific security tokens to assess account permissions.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.