Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?

⚠ Common exam trap

The trap here is assuming that execution artifacts like Prefetch or Shimcache would show the malicious DLL, but they only track executable files, not injected code within another process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Memory dumps of the injected process

DLL injection leaves artifacts in the memory of the target process. Analyzing a memory dump with forensic tools can reveal injected DLLs, often by identifying memory regions with executable permissions that are not backed by a file on disk, or by finding DLLs not listed in the process's module list. This provides direct evidence of the technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Memory dumps of the injected process

    Why this is correct

    Memory dumps of the injected process can reveal the presence of the malicious DLL in the process's address space. Tools like Volatility's malfind or dlllist can detect injected code by looking for memory regions with unusual permissions or unlinked DLLs. This is the most direct evidence of DLL injection.

  • ✗

    Windows Event Logs (Security.evtx)

    Why it's wrong here

    Security event logs record authentication and authorization events, not DLL injection. While process creation events (e.g., 4688) may show the legitimate process starting, they do not indicate that a DLL was injected into it. Event logs alone cannot confirm DLL injection; memory analysis is required.

  • ✗

    Shimcache

    Why it's wrong here

    Shimcache (AppCompatCache) tracks executables that were present on the system, not DLLs injected into running processes. It can show that a malicious executable existed, but not that it was injected into another process. Shimcache does not record DLL loading or injection events.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files record execution of applications and can show that a process ran, but they do not provide evidence of DLL injection into a legitimate process. They may show the legitimate process executed, but not that it was compromised. Prefetch is useful for proving execution, not for detecting injected code.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.