Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

⚠ Common exam trap

The trap here is selecting a network or handle plugin for injection analysis, when only memory-region plugins such as malfind and vadinfo reveal unbacked executable code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.vadinfo

windows.malfind finds executable memory regions not backed by a file, which is the signature of injected code, while windows.vadinfo provides the virtual address descriptor details for those regions, including protection and commit type. Using them together lets the analyst detect the injection and then characterize it as private, executable, and fileless within the target process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.netscan

    Why it's wrong here

    windows.netscan enumerates network connections and listening sockets from memory, which is useful for identifying command-and-control activity but does not inspect process memory for injected code. It would not reveal the injected region or its properties, so it does not fulfill the detection requirement in this scenario.

  • ✓

    windows.vadinfo

    Why this is correct

    windows.vadinfo dumps the virtual address descriptor tree for a process, showing each region's protection, commit type, and backing file. When combined with malfind, it lets you characterize the injected region by confirming whether it is private, executable, and fileless, which is essential for describing the injection in this scenario.

  • ✗

    windows.handles

    Why it's wrong here

    windows.handles lists open handles such as files, registry keys, and mutexes for each process. While useful for understanding process behavior, it does not analyze memory protections or detect unbacked executable regions, so it cannot identify or characterize the injected code described in the scenario.

  • ✗

    windows.registry.hivelist

    Why it's wrong here

    windows.registry.hivelist enumerates registry hives loaded in memory, which supports registry analysis but has no bearing on process memory protections or injected code. It cannot detect or characterize an injection, so it is not the right complement to malfind in this scenario.

  • ✓

    windows.malfind

    Why this is correct

    windows.malfind scans process virtual address space for memory regions with executable permissions that are not backed by a file on disk, which is characteristic of injected code. In this scenario it identifies the suspicious regions and the owning process, providing the starting point for characterizing the injection.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.