What Vulnerability Causes Unexpected Outbound Traffic from a Legitimate Process?

A security analyst is investigating an application server and discovers that software on the server is behaving abnormally. The software normally runs batch jobs locally and does not generate traffic, but the process is now generating outbound traffic over random high ports. Which of the following vulnerabilities has likely been exploited in this software?

  1. Memory injection Source Reference Answer
  2. Race condition
  3. Side loading
  4. SQL injection

Community Votes

A
80%
C
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the ability to distinguish between runtime memory manipulation and file-based exploitation, with the common trap being confusion between memory injection and side loading due to overlapping unauthorized execution symptoms.

This question tests recognition of memory injection attacks, where malicious code is executed directly within a legitimate process's memory space. The CompTIA Security+ community strongly agrees that unexpected outbound network traffic from a normally isolated process points to memory injection rather than side loading or other common vulnerabilities.

Many candidates incorrectly choose Side Loading because both involve unauthorized code execution, but they overlook that side loading requires the application to load an external malicious file or library, whereas the scenario describes in-memory behavioral changes without file system indicators.

Community Discussion (7 comments)

a4e15bd 👍 17
A is correct. Memory injection allows the attackers to inject malicious code directly into the memory of a running process which can then be used to execute arbitrary commands or generate unauthorized network traffic. Race Condition refers to two processes competing to modify the same resource which can lead to unpredictable behavior but is less likely to cause abnormal outbound traffic. Side Loading refers to loading a malicious DLL into a legitimate process. SQL injection involves injecting malicious SQL code into a database and is primarily concerned with database manipulation rather than generating outbound network traffic.
JoeRealCool 👍 1 Selected: A
Side loading would make sense if the question referenced changes made to the files the software uses to run. That's my understanding of the difference between side loading and memory injection. For it to be side loading, an attacker would have to place a malicious file in storage that that the software unintentionally loads and runs code off of.
test_arrow 👍 1 Selected: A
The abnormal behavior—unexpected outbound traffic over random high ports—suggests that malicious code has been injected into the application's memory. Memory injection attacks allow an attacker to execute arbitrary code within the memory space of a legitimate process, often leading to unauthorized network activity, data exfiltration, or the deployment of additional malware.
jbmac 👍 1 Selected: C
The correct answer is: C. Side loading Explanation: Side loading involves the unauthorized loading or execution of malicious code alongside legitimate software. In this scenario: The software is behaving abnormally and generating unexpected outbound traffic, which suggests it may have been compromised to execute additional, malicious code. Random high-port outbound traffic is a common indicator of malware or other unauthorized processes attempting to exfiltrate data or communicate with a command-and-control (C2) server.
chalaka 👍 2 Selected: A
A. Memory injection Memory injection vulnerabilities allow an attacker to manipulate the memory of a running application. This can lead to malicious behavior, such as executing arbitrary code or altering the application's normal operation. In this scenario, the abnormal behavior (outbound traffic over random high ports) suggests that the software has been compromised to execute unauthorized operations, which is characteristic of a memory injection exploit.
Habbiti 👍 1
The correct answer is C, side loading Side loading refers to a situation where software loads a malicious or unauthorized component or library (often from an untrusted source) instead of a legitimate one. In this case, the abnormal behavior (outbound traffic over random high ports) suggests that the application may have been compromised, and a malicious payload has been introduced, causing the software to behave unexpectedly. The random outbound traffic could indicate that the compromised software is now communicating with a command-and-control server or exfiltrating data.
jafyyy 👍 1
A. Memory Injection

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Scenario

The question presents a classic indicator of compromise (IOC): a legitimate application that normally operates in isolation suddenly generates outbound network traffic over random high ports. This behavior strongly suggests that the process has been hijacked to act as a command-and-control beacon or data exfiltration channel.

Why Memory Injection is Correct

Memory injection (often referred to as process hollowing or code injection) occurs when an attacker injects malicious payloads directly into the RAM of a running, legitimate process. As noted by multiple community experts, this technique allows attackers to execute arbitrary commands or spawn network connections without dropping additional files on disk, making it ideal for evading basic file-based monitoring. Because the malicious code runs within the trusted context of the original application, it can seamlessly initiate outbound connections on random high ports, exactly as described in the scenario.

Why Other Options Are Incorrect

Race conditions involve timing flaws where competing processes access shared resources simultaneously, typically resulting in data corruption or privilege escalation, not unauthorized network traffic generation. SQL injection targets database query construction via user input, leading to data theft or manipulation, but does not inherently cause a local batch process to open random outbound ports. Side loading, while a popular distractor, relies on the application intentionally or unintentionally loading an external malicious file or DLL. As highlighted in community discussions, side loading would leave traces in the file system or registry; the absence of such indicators and the focus on in-process behavioral anomalies make memory injection the precise technical match for this SY0-701 question.

Official Reference

  • CompTIA Security+ SY0-701 Exam Objectives: Domain 4.0 - Software and Systems Security
  • NIST SP 800-53 Rev. 5: SI-4 Information System Monitoring
  • MITRE ATT&CK Technique T1055 - Process Injection

Exam Strategy

When analyzing application behavior questions, always look for the attack vector's dependency on storage versus runtime environment. If the scenario emphasizes in-process anomalies without mentioning new files, libraries, or registry changes, prioritize memory-based exploits like injection over file-system dependent techniques like side loading or DLL hijacking.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide