GCFA Enterprise Environment Incident Response Practice Question
An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?
⚠ Common exam trap
The trap here is assuming that execution artifacts like Prefetch or Shimcache would show the malicious DLL, but they only track executable files, not injected code within another process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory dumps of the injected process
DLL injection leaves artifacts in the memory of the target process. Analyzing a memory dump with forensic tools can reveal injected DLLs, often by identifying memory regions with executable permissions that are not backed by a file on disk, or by finding DLLs not listed in the process's module list. This provides direct evidence of the technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Memory dumps of the injected process
Why this is correct
Memory dumps of the injected process can reveal the presence of the malicious DLL in the process's address space. Tools like Volatility's malfind or dlllist can detect injected code by looking for memory regions with unusual permissions or unlinked DLLs. This is the most direct evidence of DLL injection.
- ✗
Windows Event Logs (Security.evtx)
Why it's wrong here
Security event logs record authentication and authorization events, not DLL injection. While process creation events (e.g., 4688) may show the legitimate process starting, they do not indicate that a DLL was injected into it. Event logs alone cannot confirm DLL injection; memory analysis is required.
- ✗
Shimcache
Why it's wrong here
Shimcache (AppCompatCache) tracks executables that were present on the system, not DLLs injected into running processes. It can show that a malicious executable existed, but not that it was injected into another process. Shimcache does not record DLL loading or injection events.
- ✗
Prefetch files
Why it's wrong here
Prefetch files record execution of applications and can show that a process ran, but they do not provide evidence of DLL injection into a legitimate process. They may show the legitimate process executed, but not that it was compromised. Prefetch is useful for proving execution, not for detecting injected code.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.