Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which TWO of the following are Volatility plugins used for process enumeration? (Select two.)

⚠ Common exam trap

The EC-CHFI exam often tests the distinction between process enumeration plugins (pslist, pstree) and other Volatility plugins that serve different forensic purposes, such as network or file system analysis, to catch candidates who confuse plugin categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pslist

pslist (A) is a Volatility plugin that walks the active process list from the kernel's EPROCESS linked list (via PsActiveProcessHead) and prints each running process with its PID, PPID, and start time, making it a core process-enumeration plugin. pstree (C) is also a process-enumeration plugin: it uses the same process data but renders it as a parent/child tree based on PPID relationships, which helps reveal process ancestry and hidden or orphaned processes. The other options serve different forensic purposes: netscan (B) enumerates network sockets and connections, mftparser (D) parses the MFT to recover file-system metadata, and hashdump (E) extracts password hashes from the SAM registry hive, so none of them are process-enumeration plugins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    pslist

    Why this is correct

    pslist is correct because it enumerates active processes by traversing the doubly linked list of EPROCESS structures anchored at PsActiveProcessHead. This plugin reads each EPROCESS entry directly from kernel memory, extracting the process ID, parent process ID, thread counts, and creation time. It is a fundamental process listing plugin in Volatility, though it can miss processes that have been deliberately unlinked from the list to evade detection.

  • ✗

    netscan

    Why it's wrong here

    netscan is incorrect for process enumeration because it specifically looks for TCP and UDP endpoints, listeners, and connections using pool tag scanning and legacy linked-list traversal. It identifies network sockets and associated owning PIDs, but it does not enumerate all running processes. Its purpose is network artifact analysis, not process listing, so it would not be the right plugin for identifying running processes.

  • ✓

    pstree

    Why this is correct

    pstree is correct because it builds a hierarchical tree of processes by walking the same EPROCESS list as pslist but additionally uses the InheritedFromUniqueProcessId field to reconstruct parent-child relationships. This reveals the process lineage, making it easier to spot anomalies such as a document reader spawning a PowerShell process. While it shows all active processes, its primary value is the visual hierarchy rather than just a flat list.

  • ✗

    mftparser

    Why it's wrong here

    mftparser is incorrect for process listing because it parses the NTFS Master File Table (MFT) from a disk or memory image to extract file system metadata such as file names, timestamps, and data runs. It operates at the file system layer, not the kernel process layer, so it cannot identify running processes. This plugin is used in file forensics to recover deleted or hidden files, not to enumerate active EPROCESS structures.

  • ✗

    hashdump

    Why it's wrong here

    hashdump is incorrect for process enumeration because it extracts user account password hashes from the SAM registry hive loaded in memory. It locates the appropriate memory structures for the registry and parses the SAM to retrieve NTLM and LM hashes. This plugin is used for credential dumping and offline cracking, not for listing processes, and it does not interact with the EPROCESS list at all.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.