Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which THREE of the following are valid memory forensic artifacts that can be extracted using the Volatility framework?

⚠ Common exam trap

The CHFI exam often tests the distinction between file system commands (like `ls -l` or `dir /r`) and memory forensic tools (like Volatility plugins), trapping candidates who confuse operating system commands with forensic extraction methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pstree

The Volatility framework provides plugins that parse a memory image and reconstruct kernel-level data structures, so pstree (A) is valid because it walks the active process list and renders the parent-child process hierarchy from the EPROCESS structures. pslist (B) is also valid because it enumerates active processes by traversing the doubly linked list of EPROCESS objects in the kernel, a core memory-forensic artifact. netscan (D) is valid because it recovers network connection and socket artifacts (TCP/UDP endpoints, listening ports, owning PIDs) from memory pool structures. By contrast, ls -l (C) is a Linux shell command for listing filesystem directory entries, and dir /r (E) is a Windows CMD command for listing files with alternate data streams; neither is a Volatility plugin nor a memory artifact extraction technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    pstree

    Why this is correct

    The `pstree` plugin in Volatility reconstructs the full process ancestry by walking the _EPROCESS structures in the memory dump, displaying parent-child relationships. It is a critical artifact because it exposes unusual process hierarchies, such as a benign-looking child spawned by a malicious parent, which may indicate code injection or a rootkit. Unlike a flat process list, pstree shows the lineage, assisting investigators in tracing process execution paths.

  • ✓

    pslist

    Why this is correct

    The `pslist` plugin enumerates active processes by traversing the doubly-linked list of _EPROCESS objects maintained by the Windows kernel. It lists process ID, parent PID, start time, and path, providing a snapshot of what was running during acquisition. However, sophisticated malware can unlink its own structure from this linked list, making pslist blind to it, which is why it is often paired with pool-scanning alternatives.

  • ✗

    ls -l

    Why it's wrong here

    The `ls -l` command is a standard Linux utility for displaying file metadata, such as permissions, ownership, and modification times, in a live file system. It is not a memory forensics artifact and cannot parse a raw RAM dump, because memory images contain raw bytes and kernel structures rather than mounted files. Memory forensic tools like Volatility are required to interpret these structures and extract evidence.

  • ✓

    netscan

    Why this is correct

    The `netscan` plugin in Volatility scans memory for TCP and UDP endpoints by detecting pool tags associated with socket objects, such as `TcpP` and `UdpP`. It reports local and remote IP addresses, ports, and connection states (listening, established, etc.), allowing an examiner to see active network connections at the moment of capture. This artifact is particularly valuable in incident response to identify command-and-control traffic or reverse shells left in memory.

  • ✗

    dir /r

    Why it's wrong here

    `dir /r` is a Windows Command Prompt command that lists files and directories, with the `/r` switch also displaying alternate data streams (ADS). It operates only on a live NTFS volume and has no capability to read the contents of a physical memory dump. As a forensic artifact, it would be part of file system analysis, not memory analysis, and cannot expose process or network objects retained in RAM.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.