Courseiva

GCFA Introduction to Memory Forensics Practice Question

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any discrepancy between pslist and psscan automatically indicates malicious activity, when psscan can also report terminated processes or false positives due to memory reuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Processes present in windows.psscan but absent in windows.pslist are likely hidden by rootkit activity.

The correct statements highlight that windows.psscan can reveal processes hidden from the active list and may also report terminated processes whose structures remain. These behaviors are essential for detecting rootkits that unlink processes. The other statements contain factual errors about the tools' methods or draw unsupported conclusions from identical output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Processes present in windows.psscan but absent in windows.pslist are likely hidden by rootkit activity.

    Why this is correct

    windows.psscan uses pool tag scanning to find EPROCESS structures regardless of whether they are linked in the active list. If a process appears in psscan but not pslist, it suggests the process was unlinked, a common rootkit technique. This discrepancy is a key indicator of hidden processes, making this statement correct.

  • ✓

    windows.psscan may report processes that have already terminated but whose EPROCESS structures have not been overwritten.

    Why this is correct

    Pool tag scanning in windows.psscan can find EPROCESS structures that remain in memory after process termination if the memory has not been reused. These are not active processes but can provide historical evidence. This is a known behavior and an important consideration when interpreting psscan output, making this statement correct.

  • ✗

    Processes present in windows.pslist but absent in windows.psscan indicate that the process terminated normally and its memory was freed.

    Why it's wrong here

    If a process is in pslist but not psscan, it is more likely that psscan missed it due to memory corruption or that the process is in the process of terminating. However, normally terminated processes are removed from both lists. This statement is not accurate because psscan is designed to find all EPROCESS structures, so absence in psscan is unusual and not indicative of normal termination.

  • ✗

    If windows.psscan and windows.pslist produce identical output, it definitively proves that no rootkit is present on the system.

    Why it's wrong here

    Identical output does not guarantee the absence of a rootkit. Some rootkits may hide processes from both methods, or may not hide processes at all. Other rootkit techniques, such as SSDT hooking or DKOM on other structures, could still be present. Therefore, this statement is overly absolute and incorrect.

  • ✗

    windows.pslist relies on pool tag scanning, while windows.psscan walks the active process list.

    Why it's wrong here

    This statement reverses the actual methods: windows.pslist walks the active process list (via PsActiveProcessHead), while windows.psscan uses pool tag scanning. Understanding this distinction is crucial for interpreting discrepancies. Since the statement is factually incorrect, it is not a valid description of the tools' behaviors.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.