GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?
⚠ Common exam trap
Candidates often focus on file hashes or process names, which are easily spoofed, rather than inspecting memory-specific indicators like VAD tree anomalies or RWX memory regions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory Page Permissions (RWX)
Process injection techniques often modify memory protections or inject code into existing legitimate processes. By comparing the disk-based image of a process with its memory-based representation, analysts can identify discrepancies in executable sections. Checking memory protections (e.g., RWX permissions) and identifying unbacked executable code in private memory regions are the primary methods for uncovering sophisticated persistent threats that operate entirely within the volatile memory space.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Memory Page Permissions (RWX)
Why this is correct
Executable memory regions that are marked as Read-Write-Execute (RWX) are highly suspicious. Legitimate processes rarely require memory to be writable and executable simultaneously. Attackers often use these permissions to write shellcode to a buffer and then execute it, making this a primary indicator of process injection.
- ✗
The system's Event Log files
Why it's wrong here
Event logs are disk-based artifacts that do not contain the fine-grained memory structure information needed to detect process injection. While logs can show related activity, they cannot confirm the actual presence of injected code or modified memory sections within a running process's address space.
- ✓
Unbacked executable memory
Why this is correct
Memory regions that contain executable code but are not mapped to a file on disk are indicative of shellcode. In a normal process, executable code is mapped from loaded DLLs or the main binary. Code existing in private memory without a backing file is a hallmark of reflective loading.
- ✗
The MFT file records
Why it's wrong here
The MFT resides on the disk and contains metadata about the file system. It has no visibility into the volatile memory address space of running processes. It cannot be used to identify code injection or memory modifications happening within a process that is currently running in the system's RAM.
- ✓
Discrepancies in the Process VAD tree
Why this is correct
The Virtual Address Descriptor (VAD) tree tracks the memory regions allocated to a process. By analyzing the VAD tree, an investigator can identify anomalies such as memory regions that have been allocated for code storage but lack a corresponding file mapping, which is a definitive sign of process hollowing or injection.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.