GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
Which technique describes an attacker using a legitimate process to hide malicious code, commonly used to bypass security products that monitor only the primary process?
⚠ Common exam trap
Test-takers frequently confuse process hollowing with standard process injection, forgetting that hollowing specifically involves starting a process in a suspended state and replacing its memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process Hollowing
Process hollowing is a sophisticated technique where an attacker starts a legitimate process in a suspended state, replaces its memory content with a malicious payload, and then resumes the process. This is effective because security tools often trust the initial process launch and fail to inspect the subsequent memory modification. Understanding this is vital for incident handlers because it explains why legitimate-looking processes may suddenly exhibit malicious behavior during an investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLL Side-Loading
Why it's wrong here
DLL side-loading involves placing a malicious DLL with the same name as a required DLL in the application's directory to trick a trusted executable into loading the malicious code. It relies on search order vulnerabilities rather than replacing the memory content of a running, suspended process.
- ✓
Process Hollowing
Why this is correct
Process hollowing involves creating a legitimate process in a suspended state, unmapping its original memory, and replacing it with malicious code. This allows the attacker to execute their payload under the guise of a trusted, signed application, successfully bypassing many security controls that monitor for process startup patterns.
- ✗
AppInit_DLLs
Why it's wrong here
AppInit_DLLs is a mechanism that allows the loading of custom DLLs into every process that loads User32.dll. While this can be used for persistence or code injection, it is distinct from process hollowing, which specifically targets the replacement of a single process's primary memory image.
- ✗
Token Impersonation
Why it's wrong here
Token impersonation is a technique used to gain the privileges of another logged-in user. It involves stealing an access token to perform actions as that user. It is unrelated to the execution of code within a hidden memory space, which is the defining characteristic of process hollowing.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.