Courseiva

GCFA Introduction to Memory Forensics Practice Question

Exhibit

Exhibit B: Volatility vadinfo output
Virtual Address: 0x00400000
Protection: PAGE_EXECUTE_READWRITE
File: None
Tag: VadS

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

⚠ Common exam trap

Candidates often misinterpret PAGE_EXECUTE_READWRITE allocations as normal application behavior or routine caching, ignoring the strong malicious indicator of unbacked executable memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The memory segment is a malicious injection

The combination of PAGE_EXECUTE_READWRITE protection and the absence of an associated file (File: None) is a classic indicator of malicious code injection. Normal applications rarely allocate memory that is simultaneously writable and executable, as this violates standard security practices like Data Execution Prevention (DEP). The lack of a file-backing suggests the code resides entirely in memory, a common technique for fileless malware to avoid detection by traditional on-disk antivirus scanners.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The memory segment is a standard heap allocation

    Why it's wrong here

    Standard heap allocations typically use PAGE_READWRITE protection. Marking a heap segment as executable is highly anomalous and risky. Therefore, labeling this as a standard heap allocation ignores the high-risk nature of the PAGE_EXECUTE_READWRITE permission, which is a strong indicator of potential malicious activity.

  • ✓

    The memory segment is a malicious injection

    Why this is correct

    The combination of Execute, Read, and Write permissions along with the lack of file-backing is a high-confidence indicator of injected code. This configuration allows a process to write a payload to memory and then immediately execute it, which is the standard methodology for process injection attacks.

  • ✗

    The memory segment is a legitimate shared library

    Why it's wrong here

    Shared libraries (DLLs) are mapped to memory with specific protection flags, usually PAGE_EXECUTE_READ. Furthermore, they are always backed by a file on the file system. Since this segment has no file-backing and anomalous permissions, it cannot be a legitimate shared library loaded by the OS.

  • ✗

    The memory segment is part of the system kernel

    Why it's wrong here

    Kernel memory segments are managed differently than user-mode VAD entries and follow strictly defined permission models to ensure system stability. A user-mode process would not have a VAD entry with these characteristics as part of the operating system kernel. This is clearly a user-mode memory artifact.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.