GCFA Enterprise Environment Incident Response Practice Question
During an enterprise incident response, you are examining evidence on a Windows Server 2019 system that may contain a fileless malware infection. You need to determine whether a specific process was injected with malicious code. Which Windows forensic artifact is most directly useful for identifying anomalous memory regions in a process, such as those created by reflective DLL injection?
⚠ Common exam trap
The trap here is assuming that disk-based execution artifacts like Prefetch or MFT entries can reveal in-memory code injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory dump of the process
Reflective DLL injection loads a DLL directly into memory without writing it to disk, so disk-based artifacts like Prefetch or MFT entries will not show the injected code. A process memory dump captures the actual memory contents, allowing the analyst to spot anomalous regions such as executable memory not backed by a file. This makes the memory dump the most direct and reliable artifact for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MFT (Master File Table) entries
Why it's wrong here
The MFT contains metadata about files on an NTFS volume, such as timestamps and sizes. It does not track process memory or code injection. While MFT analysis can show file creation or deletion, it cannot identify anomalous memory regions within a running process. Therefore, it is not the right artifact for detecting injected code.
- ✓
Memory dump of the process
Why this is correct
A memory dump captures the full contents of a process's virtual address space, including loaded modules, heaps, stacks, and any injected code. By analyzing the dump with tools like Volatility or WinDbg, you can identify memory regions that are not backed by a file on disk (e.g., PAGE_EXECUTE_READWRITE) and detect reflective DLL injection. This directly addresses the need to find anomalous memory regions.
- ✗
Prefetch files
Why it's wrong here
Prefetch files record the execution of applications, including the files and directories accessed during startup. They can show that a process ran, but they do not provide details about memory regions or injected code. Prefetch is stored on disk and would not reveal the in-memory modifications typical of reflective DLL injection, making it unsuitable for this specific analysis.
- ✗
Windows Event Log Security log
Why it's wrong here
The Security log records events like logon attempts, privilege use, and object access. It does not contain memory layout details or code injection evidence. While it can show process creation if auditing is enabled, it cannot reveal the internal memory state of a process. Thus, it is not useful for identifying injected memory regions.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.