GCIH Incident Response and Cyber Investigation Practice Question
An incident responder is analyzing a Windows memory image and wants to identify a malicious process that has no corresponding file on disk. Which memory analysis artifact is most useful for this purpose?
⚠ Common exam trap
The trap here is assuming process creation logs or registry artifacts prove fileless execution, when only memory section mapping reveals code without an on-disk backing file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process list with associated memory sections
Memory section analysis maps each process's virtual memory regions and flags those without a corresponding file on disk. Injected or reflective-loading code appears as executable pages with no file path, which is the hallmark of a fileless process. This is the most direct way to identify a running process that never touched disk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The registry hives extracted from the memory image
Why it's wrong here
Registry hives in memory can reveal persistence mechanisms such as Run keys or services, but they do not enumerate running processes or their memory mappings. A malicious in-memory process may leave no registry footprint. Registry analysis answers persistence and configuration questions, not the presence of a fileless running process.
- ✗
The Windows event log for process creation, such as Event ID 4688
Why it's wrong here
Event ID 4688 records process creation events with the executable name and command line, but it does not show whether the executable had a backing file on disk. A fileless process may still generate a 4688 event with a legitimate-looking parent and image path. This log is useful for timeline reconstruction but insufficient to prove a process has no on-disk file.
- ✓
The process list with associated memory sections
Why this is correct
Enumerating processes and their memory sections reveals executable regions that may not map to a file on disk. Tools such as Volatility can list process memory maps and identify sections with no backing file, which is characteristic of injected or fileless code. This directly surfaces a process whose code exists only in memory, answering the scenario's need.
- ✗
The list of loaded kernel drivers
Why it's wrong here
Loaded kernel drivers reveal modules operating at ring 0, which can indicate rootkits, but they do not directly identify user-mode processes that have no on-disk file. A fileless user-mode process would not appear in the driver list. Driver enumeration answers a different question about kernel-level persistence and privilege, not user-space process origin.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.