What Vulnerability Causes Unexpected Outbound Traffic from a Legitimate Process?
A security analyst is investigating an application server and discovers that software on the server is behaving abnormally. The software normally runs batch jobs locally and does not generate traffic, but the process is now generating outbound traffic over random high ports. Which of the following vulnerabilities has likely been exploited in this software?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the ability to distinguish between runtime memory manipulation and file-based exploitation, with the common trap being confusion between memory injection and side loading due to overlapping unauthorized execution symptoms.
This question tests recognition of memory injection attacks, where malicious code is executed directly within a legitimate process's memory space. The CompTIA Security+ community strongly agrees that unexpected outbound network traffic from a normally isolated process points to memory injection rather than side loading or other common vulnerabilities.
Many candidates incorrectly choose Side Loading because both involve unauthorized code execution, but they overlook that side loading requires the application to load an external malicious file or library, whereas the scenario describes in-memory behavioral changes without file system indicators.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Scenario
The question presents a classic indicator of compromise (IOC): a legitimate application that normally operates in isolation suddenly generates outbound network traffic over random high ports. This behavior strongly suggests that the process has been hijacked to act as a command-and-control beacon or data exfiltration channel.Why Memory Injection is Correct
Memory injection (often referred to as process hollowing or code injection) occurs when an attacker injects malicious payloads directly into the RAM of a running, legitimate process. As noted by multiple community experts, this technique allows attackers to execute arbitrary commands or spawn network connections without dropping additional files on disk, making it ideal for evading basic file-based monitoring. Because the malicious code runs within the trusted context of the original application, it can seamlessly initiate outbound connections on random high ports, exactly as described in the scenario.Why Other Options Are Incorrect
Race conditions involve timing flaws where competing processes access shared resources simultaneously, typically resulting in data corruption or privilege escalation, not unauthorized network traffic generation. SQL injection targets database query construction via user input, leading to data theft or manipulation, but does not inherently cause a local batch process to open random outbound ports. Side loading, while a popular distractor, relies on the application intentionally or unintentionally loading an external malicious file or DLL. As highlighted in community discussions, side loading would leave traces in the file system or registry; the absence of such indicators and the focus on in-process behavioral anomalies make memory injection the precise technical match for this SY0-701 question.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives: Domain 4.0 - Software and Systems Security
- NIST SP 800-53 Rev. 5: SI-4 Information System Monitoring
- MITRE ATT&CK Technique T1055 - Process Injection
Exam Strategy
When analyzing application behavior questions, always look for the attack vector's dependency on storage versus runtime environment. If the scenario emphasizes in-process anomalies without mentioning new files, libraries, or registry changes, prioritize memory-based exploits like injection over file-system dependent techniques like side loading or DLL hijacking.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →