GCFA Introduction to Memory Forensics Practice Question
Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?
⚠ Common exam trap
Candidates often choose general process listing plugins like pslist, which do not inspect memory permissions or identify unbacked executable regions effectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
malfind
The 'malfind' plugin scans memory for regions that are marked as executable (X) but are not backed by a file on disk (VAD tags). This is the standard method for finding shellcode or injected DLLs, which are common in fileless malware. It matters because attackers often use memory injection to bypass signature-based antivirus, and detecting these unbacked regions is the primary way to uncover such hidden malicious execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pslist
Why it's wrong here
The pslist plugin is designed for process enumeration by traversing the active linked list. It cannot inspect the virtual memory layout of a process to identify injected code or executable memory regions that lack a corresponding file mapping, which is required to find sophisticated, fileless, or injected malicious payloads.
- ✓
malfind
Why this is correct
The malfind plugin identifies memory regions that are both executable and private (not mapped to a file on disk). This is a strong indicator of injected code, as most legitimate executables are backed by files. It is the go-to tool for finding shellcode and non-persistent malicious code running in memory.
- ✗
handles
Why it's wrong here
The handles plugin lists the resources a process has open, such as files, mutexes, and registry keys. While useful for understanding what a process is doing, it does not analyze the memory pages themselves for signs of code injection or detect executable memory regions that are not backed by files.
- ✗
dlllist
Why it's wrong here
The dlllist plugin enumerates modules that are loaded through the standard Windows loader (LDR lists). Because injected code is often hidden from these lists, dlllist will fail to reveal it. Malfind is superior because it looks at the actual memory characteristics instead of relying on the process's own internal reports.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.