GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)
⚠ Common exam trap
The trap here is focusing on generic indicators like elevated privileges or missing parent processes, which are not specific to process hollowing, rather than the memory-centric artifacts that directly reveal the technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process's image path in memory does not match the file path on disk.
Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, and injecting malicious code. This results in two key indicators: the in-memory image path may not match the disk file (or the memory content differs from disk), and threads execute from memory regions not backed by a file. These artifacts are directly tied to the hollowing technique and are detectable through memory analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process's token indicates it is running with elevated privileges.
Why it's wrong here
Elevated privileges are common for many legitimate system processes and are not a specific indicator of process hollowing. While malware might seek elevation, the presence of an elevated token alone does not suggest hollowing. The technique focuses on replacing the memory of a process, not on privilege level.
- ✓
The process's image path in memory does not match the file path on disk.
Why this is correct
In process hollowing, the original executable is created in a suspended state, its memory is unmapped, and malicious code is injected. The in-memory image path (from the PEB) may still point to the original file, but the actual code in memory is different. A mismatch between the in-memory image path and the on-disk file path, or a discrepancy in the code, is a strong indicator. This is often detected by comparing the in-memory module with the disk file.
- ✗
The process's parent process ID (PPID) is a non-existent process.
Why it's wrong here
A non-existent PPID can occur when a parent process terminates before the child, which is common and not necessarily malicious. It is not a specific indicator of process hollowing. Process hollowing involves modifying the memory of a legitimate process, often without changing its parent-child relationship. Therefore, a missing parent is not a reliable indicator.
- ✓
The process has a thread start address that points to a memory region not backed by a file on disk.
Why this is correct
Process hollowing typically results in execution starting from injected code in a memory region that is not backed by a file. The original entry point is replaced, and threads start in the injected code. Therefore, a thread start address in a non-file-backed region is highly indicative of hollowing or injection. This is a key artifact that tools like malfind detect.
- ✗
The process has a large number of open handles to remote named pipes.
Why it's wrong here
While malicious processes may use named pipes for communication, a large number of open handles to remote named pipes is not specific to process hollowing. It could indicate inter-process communication or other malicious activities, but it is not a direct indicator of hollowing. Process hollowing primarily involves memory manipulation, not handle usage.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.