GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this activity is occurring?
⚠ Common exam trap
Candidates frequently select traditional indicators like disk-based executable signatures or standard network connection ports, ignoring memory-specific anomalies such as RWX regions and unbacked modules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory regions with Read/Write/Execute (RWX) permissions within a process.
Reflective DLL injection works by loading a library from memory rather than the disk, bypassing standard file-based monitoring. Detecting this requires looking for memory-related anomalies such as memory regions with suspicious permissions (e.g., Read/Write/Execute) and the absence of a corresponding file backer for loaded modules in a process. These indicators are crucial because traditional antivirus solutions scanning the disk will miss the payload entirely as it never touches the physical storage layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Presence of a new file with an unusual extension in the system directory.
Why it's wrong here
Reflective DLL injection does not require the presence of a file on the disk. The malicious code is injected directly into the memory of a running process. Therefore, checking for new files in system directories will not reveal this type of stealthy, memory-only attack technique used by advanced adversaries.
- ✓
Memory regions with Read/Write/Execute (RWX) permissions within a process.
Why this is correct
Memory regions marked as RWX are highly unusual in normal applications. Attackers use these permissions to write their malicious code into memory and then execute it immediately. Detecting these memory segments is a primary indicator of injected code or shellcode running within the address space of a legitimate process.
- ✗
Increased usage of CPU by background system services.
Why it's wrong here
While malicious activity can consume CPU resources, high usage is a generic indicator that can be caused by software bugs, updates, or normal system operations. It lacks the specificity to reliably identify reflective DLL injection, which is typically designed to operate silently without causing significant performance degradation or system spikes.
- ✓
Loaded modules lacking a corresponding file path on the disk.
Why this is correct
Legitimate DLLs are usually backed by a physical file on the disk. When a DLL is loaded reflectively, it exists only in memory, and the operating system's module list will often show a loaded image with no associated file path. Identifying these orphaned modules is a definitive sign of memory-resident code.
- ✗
An increase in the number of network connections to unknown IPs.
Why it's wrong here
While an injected process might initiate network connections, these connections are a symptom of the malware's C2 activity rather than a sign of the injection technique itself. Many legitimate processes also create network connections, making this a low-fidelity indicator that does not specifically point toward reflective DLL injection.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.