GCFA Introduction to Memory Forensics Practice Question
Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?
⚠ Common exam trap
Candidates often confuse the TEB with the PEB, mistakenly including process-wide information like environment variables or loader data, which are stored in the PEB rather than the thread-specific TEB structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Thread Local Storage (TLS) pointers
The TEB is a user-mode structure that maintains thread-specific data, including the Thread Local Storage (TLS) array, exception handling chains, and the stack base/limit. Accessing the TEB is essential for forensic analysts because it helps decode how a specific thread executes, allows for the reconstruction of thread-local malware behavior, and provides insights into how the application manages its execution environment and exception handling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Thread Local Storage (TLS) pointers
Why this is correct
The TEB contains the TLS array, which is used by threads to store and retrieve data that is unique to that specific thread. Malware often leverages TLS callbacks to execute code before the main entry point, making the inspection of this TEB structure vital for uncovering early-stage malicious execution.
- ✓
Stack base and limit addresses
Why this is correct
The TEB stores the memory boundaries for the thread's stack. Knowing the stack base and limit is essential for forensic analysts to validate stack integrity and extract call frames. If an attacker has performed a stack overflow, these values can help identify the overflow extent during a memory analysis.
- ✓
Exception handler chain head
Why this is correct
The TEB tracks the head of the structured exception handling (SEH) chain. Attackers frequently overwrite these records to redirect execution flow when an exception occurs, a technique known as SEH hijacking. Monitoring this structure is critical for detecting exploitation attempts that rely on corrupting exception handling mechanisms for code execution.
- ✗
Active process list pointer
Why it's wrong here
The active process list is a kernel-mode structure managed by the OS executive, not the user-mode TEB. The TEB is local to the thread, whereas the process list is a global structure used by the kernel to track all running processes on the system, which is inaccessible from user-mode structures.
- ✗
Kernel-mode privilege level
Why it's wrong here
Privilege levels are managed by the processor hardware via the Current Privilege Level (CPL) and kernel-mode security tokens. The TEB is a user-mode structure and does not contain or control the security token or privilege level, as such information would be a major security vulnerability if exposed directly to user mode.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.