GSEC Endpoint Security Practice Question
A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?
⚠ Common exam trap
The trap here is assuming that built-in tools like Task Manager or Event Viewer can reveal process injection, when they only provide superficial or log-based information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process Explorer
Process Explorer provides in-depth process information, including loaded DLLs and memory contents, allowing analysts to spot suspicious or unsigned modules indicative of code injection. Task Manager, Event Viewer, and Resource Monitor lack the ability to inspect process memory in detail. Thus, Process Explorer is the correct tool for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource Monitor
Why it's wrong here
Resource Monitor shows real-time CPU, memory, disk, and network usage per process, but it does not provide details about loaded modules or memory content. It cannot identify injected code. Therefore, it is not suitable for inspecting process memory for fileless malware.
- ✓
Process Explorer
Why this is correct
Process Explorer is a Sysinternals tool that provides detailed information about running processes, including loaded DLLs, handles, and memory usage. It can show suspicious strings or unsigned modules in process memory, helping detect code injection. This makes it suitable for inspecting process memory for signs of fileless malware. Therefore, it is the correct choice.
- ✗
Task Manager
Why it's wrong here
Task Manager provides basic information about running processes, such as CPU and memory usage, but it does not allow deep inspection of process memory or loaded modules. It cannot reveal injected code or suspicious memory regions. Thus, it is not adequate for detecting fileless malware.
- ✗
Event Viewer
Why it's wrong here
Event Viewer displays system and application logs, which may contain indicators of compromise, but it does not inspect process memory. Fileless malware often leaves few traces in event logs. While useful for correlating events, it cannot directly detect code injection. Hence, it is not the correct tool for this task.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.