Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

An analyst is conducting memory forensics on a Windows system using Volatility. Which THREE commands can provide information about network connections?

⚠ Common exam trap

The CHFI exam often tests the distinction between commands that list network connections (netscan, connscan, sockets) versus those that list processes (pslist, pstree), trapping candidates who confuse process enumeration with network artifact retrieval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

netscan

Option A, netscan, is correct because it scans for network artifacts such as TCP endpoints, listening sockets, and UDP connections across all memory pools, making it the modern Volatility plugin for network connection discovery. Option C, connscan, is correct because it scans physical memory for TCP connection objects (pool tag TcpE), revealing local and remote IP addresses and ports for established connections. Option D, sockets, is correct because it enumerates socket objects in memory, showing socket handles, protocols, and associated connection details. Option B, pstree, is not correct because it displays parent-child process relationships, not network connections. Option E, pslist, is not correct because it lists active processes from the process list, which contains no network connection information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    netscan

    Why this is correct

    netscan is correct because it performs pool tag scanning to recover TCP and UDP endpoint objects from non-paged kernel memory, reliably identifying both listening and established connections on modern Windows versions. This plugin is specifically designed for network artifact extraction in memory forensics and provides complete connection tuples including local/remote IP and port, satisfying the analyst's need.

  • ✗

    pstree

    Why it's wrong here

    pstree is wrong because it reconstructs the parent-child process hierarchy from EPROCESS structures, offering invaluable insight into process relationships but containing zero network state. It cannot enumerate sockets, connections, or listening ports, so it is not the tool for discovering network-related artifacts on the system.

  • ✓

    connscan

    Why this is correct

    connscan is correct because it scans physical memory for _TCPT_OBJECT structures, which represent TCP connection objects in older Windows kernels, capturing both established and listening endpoints. While it is an older plugin and less robust than netscan on newer builds, it is a legitimate memory forensics plugin for detecting TCP connections when analyzing legacy Windows memory dumps.

  • ✓

    sockets

    Why this is correct

    sockets is correct because it enumerates _ADDRESS_OBJECT structures to list all open socket objects, identifying both TCP and UDP sockets present in memory at acquisition time. However, it only reveals the existence of sockets and their associated process, not the current connection state or peer addressing, making it a partial but valid network-focused plugin.

  • ✗

    pslist

    Why it's wrong here

    pslist is wrong because it walks the doubly linked list of EPROCESS objects to enumerate running processes and their basic metadata like PID, parent PID, and thread count. It is purely process-centric and provides no information about network connections, sockets, or communication endpoints, so it does not answer queries about network activity in memory.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.