Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

An incident responder is analyzing a suspected process injection on a Windows host. Which two artifacts most reliably indicate that a remote thread was injected into a legitimate process? (Choose two.)

⚠ Common exam trap

The trap here is conflating process creation monitoring with thread-level memory forensics, which are distinct data sources for detecting injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A memory region with PAGE_EXECUTE_READWRITE permissions that is not backed by a file on disk

Remote thread injection leaves memory artifacts: a thread whose start address is outside any loaded module, and an unbacked memory region with execute-read-write permissions. These indicate code executing from dynamically allocated memory rather than a legitimate DLL or EXE. Process creation events, failed logons, and DNS volume are unrelated to thread injection and do not directly evidence it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A memory region with PAGE_EXECUTE_READWRITE permissions that is not backed by a file on disk

    Why this is correct

    Injected code frequently resides in memory allocated with execute-read-write permissions and no corresponding file on disk. Legitimate modules are typically backed by files and have more restrictive permissions. An unbacked RWX region is a classic indicator of code injection, making it a reliable artifact to examine during memory forensics.

  • ✓

    A thread start address that resides outside the memory range of any loaded module

    Why this is correct

    When code is injected into a process, the new thread often starts at an address not backed by a legitimate module on disk. This unbacked memory region is a hallmark of injection. Legitimate threads start within known modules, so an out-of-module start address is a strong, reliable indicator of remote thread injection.

  • ✗

    Event ID 4688 showing the creation of a new process with a suspicious command line

    Why it's wrong here

    Event 4688 records process creation, not thread creation or memory anomalies. While a suspicious command line may indicate malicious activity, it does not directly evidence thread injection into another process. The question asks for artifacts of remote thread injection, so process creation logs alone are insufficient and not the most reliable indicator.

  • ✗

    An increase in DNS query volume from the host

    Why it's wrong here

    DNS query volume can indicate beaconing or exfiltration but is not specific to process injection. Injected threads do not inherently cause DNS spikes. Since the question targets memory-level artifacts of remote thread injection, DNS activity is not a reliable indicator in this context.

  • ✗

    A high number of failed logon attempts in the Security event log

    Why it's wrong here

    Failed logon attempts relate to authentication failures and brute-force or password spraying activity. They have no direct relationship to process injection or thread creation. The scenario is about memory artifacts, so failed logons are irrelevant and do not indicate remote thread injection.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.