GCFA Introduction to Memory Forensics Practice Question
Exhibit
Exhibit B: Volatility vadinfo output Virtual Address: 0x00400000 Protection: PAGE_EXECUTE_READWRITE File: None Tag: VadS
Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?
⚠ Common exam trap
Candidates often misinterpret PAGE_EXECUTE_READWRITE allocations as normal application behavior or routine caching, ignoring the strong malicious indicator of unbacked executable memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The memory segment is a malicious injection
The combination of PAGE_EXECUTE_READWRITE protection and the absence of an associated file (File: None) is a classic indicator of malicious code injection. Normal applications rarely allocate memory that is simultaneously writable and executable, as this violates standard security practices like Data Execution Prevention (DEP). The lack of a file-backing suggests the code resides entirely in memory, a common technique for fileless malware to avoid detection by traditional on-disk antivirus scanners.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The memory segment is a standard heap allocation
Why it's wrong here
Standard heap allocations typically use PAGE_READWRITE protection. Marking a heap segment as executable is highly anomalous and risky. Therefore, labeling this as a standard heap allocation ignores the high-risk nature of the PAGE_EXECUTE_READWRITE permission, which is a strong indicator of potential malicious activity.
- ✓
The memory segment is a malicious injection
Why this is correct
The combination of Execute, Read, and Write permissions along with the lack of file-backing is a high-confidence indicator of injected code. This configuration allows a process to write a payload to memory and then immediately execute it, which is the standard methodology for process injection attacks.
- ✗
The memory segment is a legitimate shared library
Why it's wrong here
Shared libraries (DLLs) are mapped to memory with specific protection flags, usually PAGE_EXECUTE_READ. Furthermore, they are always backed by a file on the file system. Since this segment has no file-backing and anomalous permissions, it cannot be a legitimate shared library loaded by the OS.
- ✗
The memory segment is part of the system kernel
Why it's wrong here
Kernel memory segments are managed differently than user-mode VAD entries and follow strictly defined permission models to ensure system stability. A user-mode process would not have a VAD entry with these characteristics as part of the operating system kernel. This is clearly a user-mode memory artifact.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.