GCFA Introduction to Memory Forensics Practice Question
In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?
⚠ Common exam trap
Candidates often confuse the VAD tree with the Page Table or physical memory structures, incorrectly attributing the mapping of virtual address spaces to lower-level hardware memory management components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To map virtual memory ranges for a process.
The VAD tree is a kernel structure used by the memory manager to keep track of the virtual memory ranges allocated to a process. It is essential for forensic analysts because it defines the memory map of a process, including which areas are executable, read-only, or writable. This structure is critical for identifying memory-resident threats that attempt to hide their presence by manipulating memory permissions to execute malicious code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To store the process execution priority.
Why it's wrong here
Process priority is managed by the kernel scheduler and stored in the EPROCESS structure and related scheduling blocks. The VAD tree is strictly concerned with managing the virtual memory space for the process and does not influence the thread scheduler's decisions about which processes receive CPU time.
- ✓
To map virtual memory ranges for a process.
Why this is correct
The VAD tree tracks all virtual memory allocations, providing the kernel with the necessary information to handle page faults and enforce memory access permissions. Forensic tools analyze the VAD tree to reconstruct the process memory map, which is necessary to identify injected code, unbacked regions, and suspicious memory attributes.
- ✗
To log all network connections made.
Why it's wrong here
Network connections are managed by the Windows network stack and TCP/IP protocol driver. Information about active network connections is maintained in separate kernel structures, such as the TCP connection table, and is not stored or represented in the process's VAD tree, which only handles memory allocation information.
- ✗
To secure the process against buffer overflows.
Why it's wrong here
The VAD tree is a bookkeeping structure, not a security mechanism. While it defines permissions, it does not actively prevent buffer overflows. Security features like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enforced by the hardware and kernel, utilizing the VAD tree to set page protections.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.