GCFA Introduction to Memory Forensics Practice Question
A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)
⚠ Common exam trap
The trap here is focusing solely on the presence of a PE header or executable permissions without considering file backing; legitimate modules are file-backed, so unbacked RWX regions with PE headers are the true indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A memory region with PAGE_EXECUTE_READWRITE protection that contains a MZ header but has no corresponding file path in the VAD.
Indicators of process injection include memory regions with PAGE_EXECUTE_READWRITE protection that are unbacked by a file on disk, especially when they contain executable headers like MZ. These characteristics suggest that code was injected directly into the process's address space, bypassing normal module loading. Legitimate code is usually backed by files and has more restrictive permissions. Therefore, the combination of RWX permissions and lack of file backing is a key red flag.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A memory region containing a PE header (MZ) that matches a known legitimate system DLL on disk.
Why it's wrong here
A memory region with a PE header matching a legitimate DLL on disk is likely a normal loaded module. While attackers can abuse legitimate DLLs through techniques like DLL hijacking, the mere presence of a matching PE header is not indicative of injection. Injection often involves unbacked regions or modifications to existing modules, so this characteristic alone does not suggest malicious activity.
- ✓
A memory region with PAGE_EXECUTE_READWRITE protection that contains a MZ header but has no corresponding file path in the VAD.
Why this is correct
This combines multiple red flags: RWX permissions, an executable header, and no file backing. The absence of a file path in the VAD means the region is unbacked, which is highly suspicious. The MZ header indicates executable content, and RWX allows modification and execution. Together, these strongly suggest that malicious code was injected into the process's memory space, as legitimate modules are file-backed and typically not RWX.
- ✗
A memory region with PAGE_READONLY protection that contains configuration data.
Why it's wrong here
PAGE_READONLY regions containing configuration data are common in legitimate processes. Such data might include strings, settings, or other non-executable content. This does not indicate code injection because the region is not executable and is read-only, meaning it cannot be used to run injected code. Analysts should focus on executable regions with suspicious permissions or content.
- ✗
A memory region with PAGE_EXECUTE_READ protection that is backed by a signed Microsoft DLL.
Why it's wrong here
A PAGE_EXECUTE_READ region backed by a signed Microsoft DLL is typical for legitimate executable code. The permissions allow execution but not modification, which is standard for loaded modules. The digital signature further indicates authenticity. This is not indicative of injection; rather, it represents normal system behavior. Injection would involve deviations from this pattern, such as unbacked or writable executable regions.
- ✓
A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk.
Why this is correct
PAGE_EXECUTE_READWRITE (RWX) permissions allow code execution and modification, which is unusual for legitimate code. When such a region is not backed by a file on disk, it suggests that code was injected directly into memory without a corresponding file. This combination is a strong indicator of process injection, as it violates the typical memory layout where executable code is mapped from files with read-only or execute-read permissions.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.