GCFA Introduction to Memory Forensics Practice Question
When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?
⚠ Common exam trap
Candidates often focus only on the MZ header, ignoring that modern fileless malware can hide by hooking system calls or modifying existing legitimate memory regions without necessarily needing a new PE header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory segments marked as PAGE_EXECUTE_READWRITE
Code injection often involves modifying existing memory segments or creating new ones with abnormal permissions. Analysts must look for areas of memory that are marked as executable but do not map to a file on disk (private memory), detect hooks in common system libraries, or identify discrepancies between memory-resident code and the original binary on disk. These indicators are classic signs that a process has been tampered with to execute malicious logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Memory segments marked as PAGE_EXECUTE_READWRITE
Why this is correct
Memory pages with Read, Write, and Execute (RWX) permissions are rare in legitimate software. These permissions are often a requirement for self-modifying code or injected payloads, making them a primary target for finding malicious code that needs to both write its payload and subsequently execute it.
- ✗
The presence of standard DLLs in the loading list
Why it's wrong here
Standard system DLLs like kernel32.dll or ntdll.dll are expected to be present in almost every process. Their existence is a sign of normal process behavior. While they can be hooked, the presence of the files themselves is not an indicator of injection or malicious activity.
- ✓
Memory regions that are executable but not file-backed
Why this is correct
Legitimate code is typically backed by an executable file on the disk. When a memory region is marked as executable but is not associated with any file (mapped memory), it strongly suggests that the code was injected directly into RAM, which is a common behavior for fileless malware.
- ✗
The thread environment block (TEB) memory region
Why it's wrong here
The TEB is used for thread-local storage and is not a common target for code injection because it is too small and structured for large payloads. While some advanced techniques may touch the TEB, it is generally not an primary indicator for identifying successful code injection compared to heap or stack.
- ✓
Discrepancy between disk and memory on-disk binaries
Why this is correct
Comparing the hash or structure of an executable on disk with the version in memory can reveal modifications. If the memory version differs from the disk version, it often indicates that an in-memory patch or infection has occurred, which is a key signature of advanced persistent threats.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.