Study. uk . com
  1. Home
  2. All questions
  3. Question 472

CompTIA Security+ study material · question 472 of 611

Why does process injection frustrate detection tools that judge activity by process name?

  1. It disables process logging
  2. It renames the malicious process
  3. It runs adversary code inside a legitimate process and inherits its privileges
  4. It runs only in kernel mode
Show the answer

Answer: C. It runs adversary code inside a legitimate process and inherits its privileges

The process name and signature remain those of the legitimate program, so name-based judgements pass it.

Challenge yourself on this topic → Study as cards