GCFA Introduction to Memory Forensics Practice Question
An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)
⚠ Common exam trap
The trap here is treating any single anomaly as proof of hollowing, when the technique is best confirmed by combining image-backing and thread-start anomalies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process's primary image memory region is not backed by the file on disk that its path indicates.
Process hollowing unmaps or overwrites the original image and injects replacement code, so the primary image region loses its legitimate file backing and threads often start in unbacked memory. Observing both an unbacked primary image and a thread starting outside known modules forms a coherent, high-confidence pattern. Pipe handles, token privilege changes, and working set size are unrelated to the hollowing technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process's token has been modified to include SeDebugPrivilege.
Why it's wrong here
SeDebugPrivilege in a token can indicate privilege escalation or debugging activity, but it is not a marker of process hollowing. Hollowing replaces image memory; it does not inherently alter the process token. This artifact is more relevant to credential or privilege investigations and does not pair with the other options to indicate hollowing.
- ✓
The process's primary image memory region is not backed by the file on disk that its path indicates.
Why this is correct
Process hollowing replaces the legitimate image with malicious code, so the in-memory image no longer matches the on-disk executable. Detecting a primary image region that is unbacked or whose contents differ from the file at the recorded path is a core indicator. This artifact alone is highly suggestive when combined with other anomalies.
- ✓
The process has a thread whose start address lies outside any legitimate loaded module.
Why this is correct
After hollowing, execution typically resumes at injected code rather than the original entry point. A thread start address that falls outside the address range of any known module indicates the thread begins in unbacked or injected memory, which is a strong corroborating sign of hollowing when paired with an unbacked primary image.
- ✗
The process has a working set larger than the system average.
Why it's wrong here
Working set size varies widely with application behavior and is a poor discriminator for hollowing. A hollowed process may even have a smaller working set than the original. Large working sets appear in browsers, databases, and many benign programs, so this observation neither supports nor refutes process hollowing and would not pair meaningfully with another artifact.
- ✗
The process has a large number of handles open to named pipes.
Why it's wrong here
Named pipe handles are common in legitimate inter-process communication and are not specific to process hollowing. Many benign applications open numerous pipe handles. While unusual handle counts may warrant attention, they do not corroborate hollowing, and this artifact would not combine with another to strongly support that conclusion.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.