Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

A security analyst is investigating a compromised Windows system and wants to see which processes were running at the time of memory capture. Which Volatility command should they use?

⚠ Common exam trap

CHFI often tests the distinction between `pslist` (which uses the kernel's process list) and `psscan` (which uses pool tag scanning), leading candidates to confuse `pslist` with other plugins like `malfind` or `netscan` that serve different forensic purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

volatility -f mem.dump pslist

The `pslist` plugin in Volatility enumerates processes from the Windows kernel's EPROCESS structure list, showing all active processes at the time of memory capture. This is the correct command to identify running processes from a memory dump, as it directly parses the doubly-linked list of process objects maintained by the kernel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    volatility -f mem.dump pslist

    Why this is correct

    The `pslist` plugin walks the doubly linked list of EPROCESS structures in the memory image, enumerating every running process at the time of capture. This directly satisfies the task of listing processes active on the compromised Windows system, making it the correct command. Note that because it relies on the linked list, processes that have deliberately unlinked themselves to evade detection will not appear, but for standard process enumeration it is the foundational Volatility command.

  • ✗

    volatility -f mem.dump hashdump

    Why it's wrong here

    The `hashdump` plugin extracts the Security Account Manager (SAM) registry hive and cached domain credentials from memory to obtain NTLM password hashes. It provides no process information whatsoever, so it cannot be used to list running processes. This command is intended for credential harvesting or auditing after a compromise, not for process enumeration, making it clearly wrong for the stated task.

  • ✗

    volatility -f mem.dump malfind

    Why it's wrong here

    The `malfind` plugin scans each process's address space for executable memory pages that are suspicious, such as PAGE_EXECUTE_READ_WRITE regions or allocations lacking a corresponding backing file, to detect code injection. It does not list processes; instead, it analyzes memory regions within processes to flag anomalies. While useful for a deeper compromise investigation, it cannot produce a simple process list, so it does not answer the question.

  • ✗

    volatility -f mem.dump netscan

    Why it's wrong here

    The `netscan` plugin enumerates active and recently closed network connections and sockets by inspecting kernel TCP/UDP endpoint structures in memory, associating them with owning process IDs. It does not provide a comprehensive list of all running processes; it only shows network-related activity. For example, a purely offline process with no sockets would not appear, making this command inadequate for full process enumeration.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.