GCFA Enterprise Environment Incident Response Practice Question
An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?
⚠ Common exam trap
The trap here is assuming that deleted-file artifacts such as MFT records or Prefetch files can reveal injected code, when injection lives in memory and is best exposed through the process VAD tree.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process's virtual address descriptor (VAD) tree and associated memory sections
The VAD tree is the memory structure that tracks every mapped region in a process, including private executable pages typical of code injection. Because injected code is often not backed by a file on disk, the VAD metadata is the most direct way to identify the anomalous region. Other artifacts like MFT records, Prefetch, or event logs may provide context but do not contain the injected code or its originating module.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security event log records in the memory image
Why it's wrong here
Event log records in memory may reveal authentication or process creation events, but the scenario states the adversary cleared the associated event log entries. Even if remnants exist, event logs do not contain the injected code region or its module origin, so they cannot satisfy the requirement.
- ✗
The Windows Prefetch file for the injected process
Why it's wrong here
Prefetch files record execution metadata such as load times and referenced files, but they do not store the contents of injected memory regions. They may show that a process ran, yet they cannot expose the injected code or its origin, making them insufficient for this memory-focused requirement.
- ✓
The process's virtual address descriptor (VAD) tree and associated memory sections
Why this is correct
The VAD tree describes each memory region mapped into the process, including private committed pages and mapped image sections. Injected code often appears as a private, executable region not backed by a file on disk. Analyzing VAD nodes and their page protections reveals suspicious executable regions and can identify the originating module even if the file was deleted.
- ✗
The MFT record for the deleted executable
Why it's wrong here
The Master File Table record may show that a file existed and was deleted, but it does not contain the injected code region or the runtime memory mapping. It can support timeline reconstruction, yet it cannot reveal the in-memory injected code or its originating module, which is what the responder needs.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.