A compromised workstation has no malicious files on disk, but EDR shows a signed system process with an unexpected executable thread and RWX memory. You need to find injected code that disk scanning missed. Which IR technique should you use?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: if the bad code is only living in RAM, your disk image can't see it. You need to grab and inspect memory to spot injected threads and RWX regions. Don't chase files when the artifact isn't on disk.
Full Explanation
Memory forensics is the correct technique because process injection can execute entirely in volatile memory, leaving little or no persistent artifact on the filesystem. The analyst captures RAM, then examines process lists, thread start addresses, module lists, memory maps, and page protections to identify code that is not backed by a legitimate executable, hidden threads, or RWX regions inside a signed process. Disk image analysis with file carving and timeline reconstruction is useful for persistent artifacts, deleted files, and temporal artifacts, but it cannot reveal code that exists only in RAM. Network packet capture with protocol anomaly baseline comparison can show C2 or lateral movement, yet it does not inspect process internals or prove injection. Static malware detonation in an isolated sandbox with YARA rules helps characterize a known sample or file, but it is not the right next step when the evidence is already inside a live process. Exam caveat: CompTIA expects you to match the artifact location to the forensics source, not choose the most advanced tool. Operational check: before analysis, acquire RAM using a trusted, validated collection tool, hash the image, and preserve the chain of custody.