Courseiva

GCFA Introduction to Memory Forensics Practice Question

A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?

⚠ Common exam trap

The trap here is assuming that a plugin named windows.netstat, similar to the live netstat command, is the best choice, when in fact windows.netscan is the Volatility 3 standard for memory-based network artifact recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.netscan

The windows.netscan plugin in Volatility 3 is specifically designed to scan memory for network connection structures and correlate them with owning processes. It provides a comprehensive view of active TCP and UDP endpoints, including local and remote addresses, ports, and process IDs. Other plugin names listed are either non-existent or less reliable, making windows.netscan the correct choice for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.netscan

    Why this is correct

    The windows.netscan plugin scans for network artifacts in memory, including TCP and UDP endpoints, and associates them with the owning process. It is designed to work across Windows versions and provides details such as local and remote addresses, ports, and process IDs. This directly meets the examiner's requirement to identify active network connections and their responsible processes.

  • ✗

    windows.sockets

    Why it's wrong here

    windows.sockets is not a standard Volatility 3 plugin. While there might be plugins for socket analysis in other frameworks, Volatility 3 uses windows.netscan for network connection enumeration. This option is a distractor and would not provide the required network connection details with process attribution.

  • ✗

    windows.netstat

    Why it's wrong here

    While windows.netstat exists in some Volatility versions, it relies on pool scanning and may not be as comprehensive or reliable as windows.netscan. In Volatility 3, windows.netscan is the recommended plugin for network artifacts. windows.netstat might miss connections or provide less accurate process attribution, making it less suitable for this scenario.

  • ✗

    windows.connections

    Why it's wrong here

    There is no Volatility 3 plugin named windows.connections. The correct plugin for network connections is windows.netscan. Using an incorrect plugin name would yield no results. The examiner should use the documented plugin for network scanning to obtain the desired information.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.