Courseiva

GCFA Introduction to Memory Forensics Practice Question

A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?

⚠ Common exam trap

The trap here is assuming that a process missing from pslist but present in psscan is merely a terminated process, when the lack of an ExitTime and the rootkit context indicate deliberate DKOM unlinking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process is hidden from the active process list due to direct kernel object manipulation (DKOM) unlinking its EPROCESS from the PsActiveProcessHead list.

The discrepancy between psscan and pslist where a process appears in pool scanning but not in the active list is a hallmark of DKOM-based process hiding. Rootkits unlink the EPROCESS from the active process list to evade detection by tools that walk that list. Pool scanning finds the structure directly in memory, revealing the hidden process. This is a fundamental technique in memory forensics for detecting stealthy malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is a legitimate service host that was terminated and its EPROCESS is lingering in pool memory before being freed.

    Why it's wrong here

    Terminated processes are unlinked from the active process list and their EPROCESS may persist briefly, but psscan typically finds them with an ExitTime set. Here, the process appears active in pool scan without an ExitTime and is hidden from the active list, which is more consistent with deliberate unlinking than normal termination. Legitimate terminated processes would also be unlinked from the list, but the lack of exit time and the rootkit context point away from this benign explanation.

  • ✗

    The process is a child of a protected process and is intentionally excluded from the active process list by Windows security features.

    Why it's wrong here

    Windows does not exclude child processes of protected processes from the active process list. Protected processes still appear in standard process enumeration tools. The exclusion from the active list in this scenario is not a documented Windows security behavior but rather a sign of manipulation. This option misattributes a rootkit artifact to a legitimate security feature.

  • ✗

    The process is a zombie process that has been reaped by its parent but its EPROCESS remains in memory due to a handle leak.

    Why it's wrong here

    Zombie processes are a Unix concept; Windows does not have zombie processes in the same sense. Even if a handle leak occurred, it would not remove the process from the active process list while leaving it in pool memory without an ExitTime. This explanation confuses Unix process semantics with Windows internals and does not match the DKOM hiding pattern.

  • ✓

    The process is hidden from the active process list due to direct kernel object manipulation (DKOM) unlinking its EPROCESS from the PsActiveProcessHead list.

    Why this is correct

    DKOM rootkits often unlink a malicious process's EPROCESS from the doubly linked list pointed to by PsActiveProcessHead, hiding it from tools that rely on that list. Pool scanning (psscan) traverses pool tags to find EPROCESS objects regardless of list membership, so it detects the hidden process. The absence of the process in pslist but presence in psscan is a classic indicator of DKOM-based process hiding.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.