Courseiva

GCFA Introduction to Memory Forensics Practice Question

Exhibit

Exhibit C: Volatility malfind output
PID: 2456 | Address: 0x00A00000 | Tag: VadS | Protection: PAGE_EXECUTE_READWRITE
Header: MZ
Content: 4D 5A 90 00 ...

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

⚠ Common exam trap

Candidates often mistake the presence of an MZ header for a simple file mapping, failing to notice that the memory region is private (not file-backed) and has suspicious RWX permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process has been infected via code injection

The presence of the 'MZ' header (the magic bytes for a Windows PE executable) in a memory region that is not backed by a file on disk (VadS) and is marked as PAGE_EXECUTE_READWRITE is definitive proof of an injected executable. The malware has loaded a complete, valid PE file directly into memory to run its payload, which is a classic indicator of advanced fileless malware that bypasses file-system-based security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is running a standard, signed driver

    Why it's wrong here

    Signed drivers are typically loaded from disk and authenticated by the Windows kernel. An injected MZ header in a non-file-backed memory region is the opposite of a signed driver. It indicates an unsigned, likely malicious, binary being executed directly from RAM to evade detection.

  • ✓

    The process has been infected via code injection

    Why this is correct

    The 'MZ' signature identifies a portable executable file. Finding this header inside a memory segment that lacks file-backing and is set to RWX permissions confirms that a complete binary payload was injected into the process memory, which is a hallmark of sophisticated process injection attacks.

  • ✗

    The process is using a standard heap allocation

    Why it's wrong here

    A heap allocation should not contain a PE header ('MZ'). If a heap segment contains an 'MZ' header, it is a sign that malicious code is residing in that memory space, not a standard heap data structure used for normal application operations.

  • ✗

    The memory segment is a legitimate shared DLL

    Why it's wrong here

    Shared DLLs are always file-backed and are not typically marked as PAGE_EXECUTE_READWRITE. The absence of file-backing for this memory segment, combined with the presence of an executable header, indicates that this is not a loaded DLL but rather an active, malicious injection.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.