Courseiva

GCFA Introduction to Memory Forensics Practice Question

A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?

⚠ Common exam trap

Many candidates confuse kernel module enumeration with driver object scanning or user-mode DLL listing, which serve different forensic purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.modules

The windows.modules plugin is designed to walk the kernel's loaded module list (PsLoadedModuleList) and display each module's name, base address, size, and path. This directly supports the analyst's goal of enumerating kernel modules from a memory image and comparing them against the operating system's reported list to identify discrepancies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.svcscan

    Why it's wrong here

    windows.svcscan lists Windows services by scanning service records in the registry and memory. While services can be related to drivers, this plugin does not directly enumerate loaded kernel modules and would not provide the base address and size information needed for module comparison.

  • ✓

    windows.modules

    Why this is correct

    The windows.modules plugin parses the kernel's module list (PsLoadedModuleList) and outputs each loaded driver, including its base address, size, and full path. This directly satisfies the requirement to enumerate kernel modules from a memory image and compare against the OS-reported list for discrepancies.

  • ✗

    windows.dlllist

    Why it's wrong here

    windows.dlllist enumerates DLLs loaded into a specific process's address space, not kernel modules. It is used for user-mode analysis and would not list kernel drivers or modules. This plugin does not meet the need to enumerate kernel modules from the memory image.

  • ✗

    windows.driverscan

    Why it's wrong here

    windows.driverscan scans pool tags to find driver objects, which can reveal unlinked drivers, but it does not produce a clean list of loaded kernel modules from the official module list. It is better suited for detecting hidden drivers, not for enumerating the standard loaded module list.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.