Which technique allows an exploit to bypass OS detection?
Which of the following allows an exploit to go undetected by the operating system?
Community Votes
60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests understanding of how attackers circumvent endpoint protection by executing directly in RAM rather than writing to disk, with the common trap being confusion between low-level hardware persistence and real-time runtime evasion.
This question explores advanced evasion techniques that bypass traditional operating system monitoring, with the majority of candidates correctly identifying memory injection as the primary method for executing malicious code without disk artifacts. While some debate firmware vulnerabilities due to their low-level nature, the consensus emphasizes in-memory execution to avoid file-based detection.
Candidates frequently select firmware vulnerabilities because firmware operates below the OS and can indeed hide from OS-level monitoring. However, firmware exploits typically focus on persistence and boot-time compromise rather than immediate exploitation undetected during runtime, making memory injection the more precise answer for bypassing active OS detection mechanisms.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: In-Memory Execution
Modern endpoint security heavily relies on file integrity monitoring, antivirus signatures, and heuristic analysis of files on disk. When an attacker uses memory injection, they write malicious code directly into the address space of a legitimate, running process. Because the payload never touches the file system, it leaves no persistent artifacts for traditional OS-level security tools to scan or flag. As noted by multiple community contributors, this technique effectively bypasses file-based detection systems entirely [1, 3, 4].Why Memory Injection is Correct
The CompTIA Security+ exam emphasizes distinguishing between persistence mechanisms and real-time evasion tactics. Memory injection (often implemented via techniques like DLL injection, reflective DLL loading, or hollowing) allows an exploit to execute directly in RAM. Since the operating system and its built-in monitors primarily track file operations and process creation, in-memory execution renders the malicious activity invisible to standard OS telemetry until behavioral anomalies are detected by advanced EDR solutions. This aligns perfectly with the question’s focus on going "undetected by the operating system."Addressing the Firmware Debate
Several candidates argued for firmware vulnerabilities (Option A), citing that firmware operates at a lower privilege level than the OS and can survive reinstallation [6, 8]. While technically true that firmware rootkits can persist across OS reinstalls, firmware exploits generally target the pre-boot environment or hardware abstraction layer. They do not typically describe a runtime exploit mechanism designed to bypass active OS monitoring during execution. The question specifically asks about allowing an exploit to go undetected, which points to runtime evasion rather than boot-stage persistence.Evaluating Other Options
Side loading (Option B) refers to installing applications outside of official app stores or package managers. It increases attack surface but does not inherently bypass OS detection mechanisms. Encrypted payloads (Option D) obfuscate data in transit or at rest, which can delay signature matching, but once decrypted in memory, the code still requires execution vectors. Encryption alone does not prevent the OS from detecting the execution process itself, making it less direct than memory injection for achieving stealthy runtime exploitation.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives (Domain 4: Threats, Attacks, and Vulnerabilities)
- MITRE ATT&CK Framework - Process Injection (TA0004/T1055)
- NIST SP 800-82 Rev. 3: Guide to Industrial Control Systems Security
- Microsoft Docs - Advanced Threat Protection: In-Memory Attack Techniques
Exam Strategy
When faced with questions about evasion techniques, carefully distinguish between persistence (staying hidden after reboot/reinstall) and runtime evasion (bypassing active monitoring during execution). Look for keywords like "undetected," "real-time," or "file-based" to guide you toward in-memory or obfuscation answers, while reserving low-level/hardware options for boot-level or persistence-focused scenarios. Always prioritize the option that directly addresses the specific phase of the attack lifecycle described in the prompt.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →