GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)
⚠ Common exam trap
The trap here is selecting a network or handle plugin for injection analysis, when only memory-region plugins such as malfind and vadinfo reveal unbacked executable code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.vadinfo
windows.malfind finds executable memory regions not backed by a file, which is the signature of injected code, while windows.vadinfo provides the virtual address descriptor details for those regions, including protection and commit type. Using them together lets the analyst detect the injection and then characterize it as private, executable, and fileless within the target process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.netscan
Why it's wrong here
windows.netscan enumerates network connections and listening sockets from memory, which is useful for identifying command-and-control activity but does not inspect process memory for injected code. It would not reveal the injected region or its properties, so it does not fulfill the detection requirement in this scenario.
- ✓
windows.vadinfo
Why this is correct
windows.vadinfo dumps the virtual address descriptor tree for a process, showing each region's protection, commit type, and backing file. When combined with malfind, it lets you characterize the injected region by confirming whether it is private, executable, and fileless, which is essential for describing the injection in this scenario.
- ✗
windows.handles
Why it's wrong here
windows.handles lists open handles such as files, registry keys, and mutexes for each process. While useful for understanding process behavior, it does not analyze memory protections or detect unbacked executable regions, so it cannot identify or characterize the injected code described in the scenario.
- ✗
windows.registry.hivelist
Why it's wrong here
windows.registry.hivelist enumerates registry hives loaded in memory, which supports registry analysis but has no bearing on process memory protections or injected code. It cannot detect or characterize an injection, so it is not the right complement to malfind in this scenario.
- ✓
windows.malfind
Why this is correct
windows.malfind scans process virtual address space for memory regions with executable permissions that are not backed by a file on disk, which is characteristic of injected code. In this scenario it identifies the suspicious regions and the owning process, providing the starting point for characterizing the injection.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.