GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An incident responder is analyzing a suspected process injection on a Windows host. Which two artifacts most reliably indicate that a remote thread was injected into a legitimate process? (Choose two.)
⚠ Common exam trap
The trap here is conflating process creation monitoring with thread-level memory forensics, which are distinct data sources for detecting injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A memory region with PAGE_EXECUTE_READWRITE permissions that is not backed by a file on disk
Remote thread injection leaves memory artifacts: a thread whose start address is outside any loaded module, and an unbacked memory region with execute-read-write permissions. These indicate code executing from dynamically allocated memory rather than a legitimate DLL or EXE. Process creation events, failed logons, and DNS volume are unrelated to thread injection and do not directly evidence it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A memory region with PAGE_EXECUTE_READWRITE permissions that is not backed by a file on disk
Why this is correct
Injected code frequently resides in memory allocated with execute-read-write permissions and no corresponding file on disk. Legitimate modules are typically backed by files and have more restrictive permissions. An unbacked RWX region is a classic indicator of code injection, making it a reliable artifact to examine during memory forensics.
- ✓
A thread start address that resides outside the memory range of any loaded module
Why this is correct
When code is injected into a process, the new thread often starts at an address not backed by a legitimate module on disk. This unbacked memory region is a hallmark of injection. Legitimate threads start within known modules, so an out-of-module start address is a strong, reliable indicator of remote thread injection.
- ✗
Event ID 4688 showing the creation of a new process with a suspicious command line
Why it's wrong here
Event 4688 records process creation, not thread creation or memory anomalies. While a suspicious command line may indicate malicious activity, it does not directly evidence thread injection into another process. The question asks for artifacts of remote thread injection, so process creation logs alone are insufficient and not the most reliable indicator.
- ✗
An increase in DNS query volume from the host
Why it's wrong here
DNS query volume can indicate beaconing or exfiltration but is not specific to process injection. Injected threads do not inherently cause DNS spikes. Since the question targets memory-level artifacts of remote thread injection, DNS activity is not a reliable indicator in this context.
- ✗
A high number of failed logon attempts in the Security event log
Why it's wrong here
Failed logon attempts relate to authentication failures and brute-force or password spraying activity. They have no direct relationship to process injection or thread creation. The scenario is about memory artifacts, so failed logons are irrelevant and do not indicate remote thread injection.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.