Courseiva

GCFA Introduction to Memory Forensics Practice Question

In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?

⚠ Common exam trap

Candidates often confuse the VAD tree with the Page Table or physical memory structures, incorrectly attributing the mapping of virtual address spaces to lower-level hardware memory management components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To map virtual memory ranges for a process.

The VAD tree is a kernel structure used by the memory manager to keep track of the virtual memory ranges allocated to a process. It is essential for forensic analysts because it defines the memory map of a process, including which areas are executable, read-only, or writable. This structure is critical for identifying memory-resident threats that attempt to hide their presence by manipulating memory permissions to execute malicious code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To store the process execution priority.

    Why it's wrong here

    Process priority is managed by the kernel scheduler and stored in the EPROCESS structure and related scheduling blocks. The VAD tree is strictly concerned with managing the virtual memory space for the process and does not influence the thread scheduler's decisions about which processes receive CPU time.

  • ✓

    To map virtual memory ranges for a process.

    Why this is correct

    The VAD tree tracks all virtual memory allocations, providing the kernel with the necessary information to handle page faults and enforce memory access permissions. Forensic tools analyze the VAD tree to reconstruct the process memory map, which is necessary to identify injected code, unbacked regions, and suspicious memory attributes.

  • ✗

    To log all network connections made.

    Why it's wrong here

    Network connections are managed by the Windows network stack and TCP/IP protocol driver. Information about active network connections is maintained in separate kernel structures, such as the TCP connection table, and is not stored or represented in the process's VAD tree, which only handles memory allocation information.

  • ✗

    To secure the process against buffer overflows.

    Why it's wrong here

    The VAD tree is a bookkeeping structure, not a security mechanism. While it defines permissions, it does not actively prevent buffer overflows. Security features like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enforced by the hardware and kernel, utilizing the VAD tree to set page protections.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.