GCFA • Practice Test 4
Free GCFA practice test — 10 questions with explanations. Set 4. No signup required.
During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.