- Home
- All questions
- Question 472
CompTIA Security+ study material · question 472 of 611
Why does process injection frustrate detection tools that judge activity by process name?
Show the answer
Answer: C. It runs adversary code inside a legitimate process and inherits its privileges
The process name and signature remain those of the legitimate program, so name-based judgements pass it.