Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

⚠ Common exam trap

Candidates often focus on file hashes or process names, which are easily spoofed, rather than inspecting memory-specific indicators like VAD tree anomalies or RWX memory regions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Memory Page Permissions (RWX)

Process injection techniques often modify memory protections or inject code into existing legitimate processes. By comparing the disk-based image of a process with its memory-based representation, analysts can identify discrepancies in executable sections. Checking memory protections (e.g., RWX permissions) and identifying unbacked executable code in private memory regions are the primary methods for uncovering sophisticated persistent threats that operate entirely within the volatile memory space.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Memory Page Permissions (RWX)

    Why this is correct

    Executable memory regions that are marked as Read-Write-Execute (RWX) are highly suspicious. Legitimate processes rarely require memory to be writable and executable simultaneously. Attackers often use these permissions to write shellcode to a buffer and then execute it, making this a primary indicator of process injection.

  • ✗

    The system's Event Log files

    Why it's wrong here

    Event logs are disk-based artifacts that do not contain the fine-grained memory structure information needed to detect process injection. While logs can show related activity, they cannot confirm the actual presence of injected code or modified memory sections within a running process's address space.

  • ✓

    Unbacked executable memory

    Why this is correct

    Memory regions that contain executable code but are not mapped to a file on disk are indicative of shellcode. In a normal process, executable code is mapped from loaded DLLs or the main binary. Code existing in private memory without a backing file is a hallmark of reflective loading.

  • ✗

    The MFT file records

    Why it's wrong here

    The MFT resides on the disk and contains metadata about the file system. It has no visibility into the volatile memory address space of running processes. It cannot be used to identify code injection or memory modifications happening within a process that is currently running in the system's RAM.

  • ✓

    Discrepancies in the Process VAD tree

    Why this is correct

    The Virtual Address Descriptor (VAD) tree tracks the memory regions allocated to a process. By analyzing the VAD tree, an investigator can identify anomalies such as memory regions that have been allocated for code storage but lack a corresponding file mapping, which is a definitive sign of process hollowing or injection.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.