Courseiva
Endpoint Security →mediumMultiple Choice

GSEC Endpoint Security Practice Question

A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?

⚠ Common exam trap

The trap here is assuming that built-in tools like Task Manager or Event Viewer can reveal process injection, when they only provide superficial or log-based information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Process Explorer

Process Explorer provides in-depth process information, including loaded DLLs and memory contents, allowing analysts to spot suspicious or unsigned modules indicative of code injection. Task Manager, Event Viewer, and Resource Monitor lack the ability to inspect process memory in detail. Thus, Process Explorer is the correct tool for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Resource Monitor

    Why it's wrong here

    Resource Monitor shows real-time CPU, memory, disk, and network usage per process, but it does not provide details about loaded modules or memory content. It cannot identify injected code. Therefore, it is not suitable for inspecting process memory for fileless malware.

  • ✓

    Process Explorer

    Why this is correct

    Process Explorer is a Sysinternals tool that provides detailed information about running processes, including loaded DLLs, handles, and memory usage. It can show suspicious strings or unsigned modules in process memory, helping detect code injection. This makes it suitable for inspecting process memory for signs of fileless malware. Therefore, it is the correct choice.

  • ✗

    Task Manager

    Why it's wrong here

    Task Manager provides basic information about running processes, such as CPU and memory usage, but it does not allow deep inspection of process memory or loaded modules. It cannot reveal injected code or suspicious memory regions. Thus, it is not adequate for detecting fileless malware.

  • ✗

    Event Viewer

    Why it's wrong here

    Event Viewer displays system and application logs, which may contain indicators of compromise, but it does not inspect process memory. Fileless malware often leaves few traces in event logs. While useful for correlating events, it cannot directly detect code injection. Hence, it is not the correct tool for this task.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.