Courseiva

GCFA Introduction to Memory Forensics Practice Question

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

⚠ Common exam trap

Candidates often confuse the TEB with the PEB, mistakenly including process-wide information like environment variables or loader data, which are stored in the PEB rather than the thread-specific TEB structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Thread Local Storage (TLS) pointers

The TEB is a user-mode structure that maintains thread-specific data, including the Thread Local Storage (TLS) array, exception handling chains, and the stack base/limit. Accessing the TEB is essential for forensic analysts because it helps decode how a specific thread executes, allows for the reconstruction of thread-local malware behavior, and provides insights into how the application manages its execution environment and exception handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Thread Local Storage (TLS) pointers

    Why this is correct

    The TEB contains the TLS array, which is used by threads to store and retrieve data that is unique to that specific thread. Malware often leverages TLS callbacks to execute code before the main entry point, making the inspection of this TEB structure vital for uncovering early-stage malicious execution.

  • ✓

    Stack base and limit addresses

    Why this is correct

    The TEB stores the memory boundaries for the thread's stack. Knowing the stack base and limit is essential for forensic analysts to validate stack integrity and extract call frames. If an attacker has performed a stack overflow, these values can help identify the overflow extent during a memory analysis.

  • ✓

    Exception handler chain head

    Why this is correct

    The TEB tracks the head of the structured exception handling (SEH) chain. Attackers frequently overwrite these records to redirect execution flow when an exception occurs, a technique known as SEH hijacking. Monitoring this structure is critical for detecting exploitation attempts that rely on corrupting exception handling mechanisms for code execution.

  • ✗

    Active process list pointer

    Why it's wrong here

    The active process list is a kernel-mode structure managed by the OS executive, not the user-mode TEB. The TEB is local to the thread, whereas the process list is a global structure used by the kernel to track all running processes on the system, which is inaccessible from user-mode structures.

  • ✗

    Kernel-mode privilege level

    Why it's wrong here

    Privilege levels are managed by the processor hardware via the Current Privilege Level (CPL) and kernel-mode security tokens. The TEB is a user-mode structure and does not contain or control the security token or privilege level, as such information would be a major security vulnerability if exposed directly to user mode.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.