Courseiva

GCFA Introduction to Memory Forensics Practice Question

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

⚠ Common exam trap

Test-takers often misattribute PEB and VAD tree discrepancies to simple file corruption or benign application updates rather than recognizing advanced process hollowing techniques.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process structures in memory

Discrepancies between the PEB and the Virtual Address Descriptor (VAD) tree often indicate process hollowing or replacement. Malware frequently updates the PEB image path to masquerade as legitimate system services while the VAD tree reflects the actual memory mapping of the injected code. Identifying this mismatch is critical for uncovering stealthy code injection techniques that bypass simple process listing tools by hiding the true origin of the executable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Master File Table (MFT) entry

    Why it's wrong here

    The MFT entry resides on the physical disk and tracks file metadata like timestamps and allocation status. While an examiner might compare memory paths to disk paths, the MFT itself is not the structure manipulated to cause a PEB-to-VAD discrepancy within the memory-resident process structures.

  • ✗

    The Thread Environment Block (TEB)

    Why it's wrong here

    The TEB stores thread-specific information such as the thread local storage and stack pointers. While relevant for analyzing execution flow and synchronization, it does not store the primary executable path for the process, making it an unlikely target for path-based masquerading attacks in memory.

  • ✓

    The process structures in memory

    Why this is correct

    Process hollowing involves creating a legitimate process in a suspended state and replacing its memory contents. The operating system maintains the PEB for legacy application compatibility, but the VAD tree manages the actual memory ranges mapped to the process. Mismatches here are a hallmark of process injection.

  • ✗

    The System Service Descriptor Table (SSDT)

    Why it's wrong here

    The SSDT is used by the kernel to dispatch system calls. While rootkits may hook the SSDT to hide files or network connections, modifying this table does not cause the specific discrepancy between the PEB path and VAD tree entries observed for a single malicious process.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.