GCFA Introduction to Memory Forensics Practice Question
A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?
⚠ Common exam trap
Many candidates confuse kernel module enumeration with driver object scanning or user-mode DLL listing, which serve different forensic purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.modules
The windows.modules plugin is designed to walk the kernel's loaded module list (PsLoadedModuleList) and display each module's name, base address, size, and path. This directly supports the analyst's goal of enumerating kernel modules from a memory image and comparing them against the operating system's reported list to identify discrepancies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.svcscan
Why it's wrong here
windows.svcscan lists Windows services by scanning service records in the registry and memory. While services can be related to drivers, this plugin does not directly enumerate loaded kernel modules and would not provide the base address and size information needed for module comparison.
- ✓
windows.modules
Why this is correct
The windows.modules plugin parses the kernel's module list (PsLoadedModuleList) and outputs each loaded driver, including its base address, size, and full path. This directly satisfies the requirement to enumerate kernel modules from a memory image and compare against the OS-reported list for discrepancies.
- ✗
windows.dlllist
Why it's wrong here
windows.dlllist enumerates DLLs loaded into a specific process's address space, not kernel modules. It is used for user-mode analysis and would not list kernel drivers or modules. This plugin does not meet the need to enumerate kernel modules from the memory image.
- ✗
windows.driverscan
Why it's wrong here
windows.driverscan scans pool tags to find driver objects, which can reveal unlinked drivers, but it does not produce a clean list of loaded kernel modules from the official module list. It is better suited for detecting hidden drivers, not for enumerating the standard loaded module list.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.