Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?

⚠ Common exam trap

Students often look for traditional executable files on the disk, failing to select memory-based indicators like encoded PowerShell commands and injected process code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evidence of PowerShell execution using the -EncodedCommand flag.

Fileless malware operates by residing in volatile memory rather than writing traditional binaries to the disk. Analysts must focus on process memory injection, anomalous script execution, and reflective DLL loading. Detecting these requires memory forensics tools to extract and analyze injected code segments or PowerShell command history. This is critical because attackers increasingly use living-off-the-land techniques to evade signature-based antivirus solutions that primarily scan files on disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Creation of an autorun registry key pointing to a hidden .exe file.

    Why it's wrong here

    Registry keys pointing to .exe files on disk are traditional persistent methods. Fileless malware avoids this by using techniques like WMI event consumers or malicious PowerShell scripts stored in registry values, rather than relying on standard disk-based binaries that trigger signature-based detection mechanisms during normal system boot sequences.

  • ✓

    Evidence of PowerShell execution using the -EncodedCommand flag.

    Why this is correct

    Using -EncodedCommand is a classic tactic to hide malicious PowerShell logic from simple string-based logging. Forensic analysts frequently encounter this in fileless attacks, where the script is base64-encoded and passed directly into memory, leaving no direct trace of the script file on the local file system.

  • ✓

    Injected code found within the memory space of a legitimate process.

    Why this is correct

    Memory injection into a legitimate process like lsass.exe or explorer.exe is a primary tactic for fileless persistence. By executing code inside a trusted process's memory space, attackers evade detection and maintain stealthy execution without needing to drop any physical files onto the machine's primary storage drive.

  • ✗

    Large volume of deleted files recovered from the $MFT.

    Why it's wrong here

    Large deletions of files in the Master File Table are indicators of anti-forensics or cleanup after a traditional malware infection. This does not describe fileless execution, which specifically aims to avoid creating disk artifacts in the first place, thus rendering MFT analysis less effective for this specific threat type.

  • ✗

    High frequency of DLL load events from the C:\Windows\Temp directory.

    Why it's wrong here

    Loading DLLs from temporary directories is a common trait of droppers or traditional malware installations. While potentially suspicious, it is distinct from fileless execution, which prefers reflective loading or in-memory execution. This behavior relates more to standard persistent malware delivery than the stealthy, non-disk-resident nature of fileless attacks.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.