GCFA Introduction to Memory Forensics Practice Question
A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)
⚠ Common exam trap
The trap here is treating any unusual process characteristic, such as a DLL loaded from AppData or a high handle count, as proof of injection, when injection specifically requires executable code in an unbacked region or a thread executing outside known modules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk
Process injection typically manifests as executable memory that is not backed by a file on disk and as threads whose start addresses fall outside any mapped module. These two findings together provide strong evidence that an attacker wrote and executed code within another process, whereas handle counts, working set ratios, and AppData DLL loads have legitimate explanations and are not specific to injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A process with a large number of handles to named pipes
Why it's wrong here
Many named pipe handles can indicate inter-process communication or even malware command-and-control, but it is not specific to code injection. Legitimate services and applications also open numerous pipes, so this finding alone does not demonstrate that executable code was injected into the process address space.
- ✗
A process whose working set is larger than its private commit size
Why it's wrong here
The relationship between working set and private commit size reflects memory pressure and paging behavior, not injection. Injected code can exist in a small region, and legitimate processes can have large working sets, so this metric does not distinguish an injected process from a normal one and is not a reliable indicator.
- ✓
A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk
Why this is correct
Executable and writable memory that has no file backing is a classic indicator of injected code, because legitimate executables and DLLs are normally mapped from disk with read-only or execute-only protections. The combination of writability, executability, and no on-disk source strongly suggests an attacker allocated memory and wrote shellcode or a payload into it.
- ✗
A DLL loaded from a path within the user's AppData directory
Why it's wrong here
A DLL loaded from AppData is suspicious and may indicate DLL search order hijacking or side-loading, but it is still a file-backed module on disk. It does not demonstrate that code was injected into unbacked memory, so it is not the strongest indicator of process injection compared with executable unbacked regions and anomalous thread start addresses.
- ✓
A thread whose start address falls outside any known module range in the process
Why this is correct
A thread start address that does not resolve to a loaded module indicates the thread was created to execute code in an unbacked region, which is typical of injection techniques such as CreateRemoteThread with a shellcode payload. Legitimate threads normally begin execution inside a mapped executable or DLL, so this finding is highly suspicious.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.