A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
Start practicing
Introduction to Memory Forensics — choose a session length
Free · No account required
Domain overview
This domain covers acquiring and interpreting Windows memory images with Volatility 3, focusing on detecting fileless malware, hidden or unlinked processes, and network artifacts from terminated processes. Questions present realistic incident scenarios and require selecting the correct plugin, interpreting its output, and drawing defensible forensic conclusions from memory-resident evidence.
Exam objectives
Running windows.malfind to locate injected or suspicious executable memory regions in a process
Using windows.psscan to find processes unlinked from the active process list
Correlating windows.netscan connections with processes absent from windows.pslist
Understanding WinPmem acquisition and what a full physical memory image contains
Assuming windows.pslist shows all processes; rootkits can unlink processes, so windows.psscan is needed to reveal hidden ones
Treating any malfind hit as confirmed malware; legitimate injected or packed code can also appear, so corroborate with other artifacts
Concluding a network connection is inactive because its process is missing from pslist, when the process may simply be terminated or hidden
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?
2An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?
3Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?
4An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?
5Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?
6When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?
7When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?
8Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?
9When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?
10An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?
11Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?
12Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?
13Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?
14Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?
15You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?
16Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?
17When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?
18Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?
19In the context of memory forensics, what does the term 'Page File' represent in a crash dump?
20Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?
21In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?
22When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?
23A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?
24During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?
25A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?
26An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?
27An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?
28An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?
29You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?
30An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?
31A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)
32A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)
33An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)
34A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?
35During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?
36A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?
37You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?
38During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?
39A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)
40During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?
41You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)
42You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?
43A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?
44An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?
45A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?
46An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?
47During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?
48A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?
49A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)
50A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?
51An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?
52A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)
53An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?
A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
The Courseiva GCFA question bank contains 53 questions in the Introduction to Memory Forensics domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Introduction to Memory Forensics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included