GCFA Introduction to Memory Forensics Practice Question
Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?
⚠ Common exam trap
Candidates often look for the user's profile path or environmental variables, which can be spoofed, rather than the kernel-level security token which serves as the authoritative source for process identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process security token
In Windows, every process is associated with a security token object that defines the user's identity, privileges, and groups. By extracting the security token structure associated with an EPROCESS object in memory, an analyst can determine the exact user context under which the process is executing. This is vital for determining if a process was launched with system privileges or by a compromised local user account during an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The thread environment block (TEB)
Why it's wrong here
The TEB is specific to a thread and contains thread-local storage data. It does not hold the primary security token for the entire process. Security context is defined at the process level, making the TEB an incorrect source for identifying the user account that owns the process.
- ✓
The process security token
Why this is correct
The process security token is a kernel object that represents the user's security context. It contains the SIDs for the user and their groups, which directly indicate the account identity that owns the process, providing the necessary evidence for identifying which user account executed the malware.
- ✗
The process environment block (PEB)
Why it's wrong here
The PEB stores configuration and environment information for the process but not the security token. While it tells you how the process was started, it does not explicitly define the security identity of the account that owns the process, which is handled by kernel security objects.
- ✗
The registry hive file for the user
Why it's wrong here
Registry hives are on-disk files. While they might show what programs a user has run in the past, they do not provide real-time information about which user owns a process currently active in memory. Memory forensic tools must parse kernel structures to determine the owner of active processes.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.