Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?

⚠ Common exam trap

The trap here is assuming that deleted-file artifacts such as MFT records or Prefetch files can reveal injected code, when injection lives in memory and is best exposed through the process VAD tree.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process's virtual address descriptor (VAD) tree and associated memory sections

The VAD tree is the memory structure that tracks every mapped region in a process, including private executable pages typical of code injection. Because injected code is often not backed by a file on disk, the VAD metadata is the most direct way to identify the anomalous region. Other artifacts like MFT records, Prefetch, or event logs may provide context but do not contain the injected code or its originating module.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Security event log records in the memory image

    Why it's wrong here

    Event log records in memory may reveal authentication or process creation events, but the scenario states the adversary cleared the associated event log entries. Even if remnants exist, event logs do not contain the injected code region or its module origin, so they cannot satisfy the requirement.

  • ✗

    The Windows Prefetch file for the injected process

    Why it's wrong here

    Prefetch files record execution metadata such as load times and referenced files, but they do not store the contents of injected memory regions. They may show that a process ran, yet they cannot expose the injected code or its origin, making them insufficient for this memory-focused requirement.

  • ✓

    The process's virtual address descriptor (VAD) tree and associated memory sections

    Why this is correct

    The VAD tree describes each memory region mapped into the process, including private committed pages and mapped image sections. Injected code often appears as a private, executable region not backed by a file on disk. Analyzing VAD nodes and their page protections reveals suspicious executable regions and can identify the originating module even if the file was deleted.

  • ✗

    The MFT record for the deleted executable

    Why it's wrong here

    The Master File Table record may show that a file existed and was deleted, but it does not contain the injected code region or the runtime memory mapping. It can support timeline reconstruction, yet it cannot reveal the in-memory injected code or its originating module, which is what the responder needs.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.