GCFA Introduction to Memory Forensics Practice Question
A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?
⚠ Common exam trap
The trap here is assuming that a plugin named windows.netstat, similar to the live netstat command, is the best choice, when in fact windows.netscan is the Volatility 3 standard for memory-based network artifact recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.netscan
The windows.netscan plugin in Volatility 3 is specifically designed to scan memory for network connection structures and correlate them with owning processes. It provides a comprehensive view of active TCP and UDP endpoints, including local and remote addresses, ports, and process IDs. Other plugin names listed are either non-existent or less reliable, making windows.netscan the correct choice for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
windows.netscan
Why this is correct
The windows.netscan plugin scans for network artifacts in memory, including TCP and UDP endpoints, and associates them with the owning process. It is designed to work across Windows versions and provides details such as local and remote addresses, ports, and process IDs. This directly meets the examiner's requirement to identify active network connections and their responsible processes.
- ✗
windows.sockets
Why it's wrong here
windows.sockets is not a standard Volatility 3 plugin. While there might be plugins for socket analysis in other frameworks, Volatility 3 uses windows.netscan for network connection enumeration. This option is a distractor and would not provide the required network connection details with process attribution.
- ✗
windows.netstat
Why it's wrong here
While windows.netstat exists in some Volatility versions, it relies on pool scanning and may not be as comprehensive or reliable as windows.netscan. In Volatility 3, windows.netscan is the recommended plugin for network artifacts. windows.netstat might miss connections or provide less accurate process attribution, making it less suitable for this scenario.
- ✗
windows.connections
Why it's wrong here
There is no Volatility 3 plugin named windows.connections. The correct plugin for network connections is windows.netscan. Using an incorrect plugin name would yield no results. The examiner should use the documented plugin for network scanning to obtain the desired information.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.