Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)

⚠ Common exam trap

The trap here is assuming that pstree provides an independent process enumeration method; it actually uses the same active process list as pslist and does not scan for hidden processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.pslist

windows.pslist enumerates processes from the active process list, while windows.psscan scans memory for process structures, which can uncover terminated or hidden processes. Using both provides a more comprehensive view of processes that were running or had recently terminated. The other plugins either rely on the same active list or serve different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.pslist

    Why this is correct

    windows.pslist walks the active process list (PsActiveProcessHead) to enumerate processes that were active at the time of capture. It provides a list of processes with their PIDs, PPIDs, and other details, but it may miss processes that have terminated or are hidden.

  • ✗

    windows.handles

    Why it's wrong here

    windows.handles lists open handles for processes, which can be useful for analyzing resource usage, but it does not enumerate processes from a different source. It requires a process list to operate and does not reveal terminated or hidden processes.

  • ✓

    windows.psscan

    Why this is correct

    windows.psscan scans for process structures in memory by looking for pool tags and other patterns, which can reveal terminated or hidden processes not present in the active list. It complements pslist by finding processes that may have been unlinked.

  • ✗

    windows.cmdline

    Why it's wrong here

    windows.cmdline retrieves command line arguments for processes, but it does not enumerate processes from a different source. It depends on the process list and is used to extract additional details, not to discover processes that may be hidden or terminated.

  • ✗

    windows.pstree

    Why it's wrong here

    windows.pstree displays processes in a tree structure based on parent-child relationships, but it relies on the same active process list as pslist. It does not independently scan for terminated or hidden processes, so it does not provide a different source of process enumeration.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.