Courseiva

GCFA Introduction to Memory Forensics Practice Question

Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?

⚠ Common exam trap

Candidates often look for the user's profile path or environmental variables, which can be spoofed, rather than the kernel-level security token which serves as the authoritative source for process identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process security token

In Windows, every process is associated with a security token object that defines the user's identity, privileges, and groups. By extracting the security token structure associated with an EPROCESS object in memory, an analyst can determine the exact user context under which the process is executing. This is vital for determining if a process was launched with system privileges or by a compromised local user account during an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The thread environment block (TEB)

    Why it's wrong here

    The TEB is specific to a thread and contains thread-local storage data. It does not hold the primary security token for the entire process. Security context is defined at the process level, making the TEB an incorrect source for identifying the user account that owns the process.

  • ✓

    The process security token

    Why this is correct

    The process security token is a kernel object that represents the user's security context. It contains the SIDs for the user and their groups, which directly indicate the account identity that owns the process, providing the necessary evidence for identifying which user account executed the malware.

  • ✗

    The process environment block (PEB)

    Why it's wrong here

    The PEB stores configuration and environment information for the process but not the security token. While it tells you how the process was started, it does not explicitly define the security identity of the account that owns the process, which is handled by kernel security objects.

  • ✗

    The registry hive file for the user

    Why it's wrong here

    Registry hives are on-disk files. While they might show what programs a user has run in the past, they do not provide real-time information about which user owns a process currently active in memory. Memory forensic tools must parse kernel structures to determine the owner of active processes.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.