GCFA Introduction to Memory Forensics Practice Question
A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?
⚠ Common exam trap
The trap here is assuming that terminated processes are completely removed from memory, but their structures can linger until overwritten, which psscan can detect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.psscan
The windows.psscan plugin scans physical memory for process objects, which allows it to find processes that have been terminated but whose structures have not been overwritten. This is useful for identifying residual evidence from terminated processes. In contrast, pslist and pstree only show active processes, and cmdline provides arguments for active processes. Therefore, psscan is the correct choice for finding terminated processes in a memory dump.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.cmdline
Why it's wrong here
windows.cmdline displays command-line arguments for active processes, which can provide context but does not list terminated processes. It relies on active process structures and would not show residual information from terminated processes. Hence, it is not the appropriate plugin for this task.
- ✓
windows.psscan
Why this is correct
windows.psscan scans physical memory for process objects, including those that have been terminated but not yet overwritten. It can find residual process structures that are no longer in the active process list. This makes it the correct plugin to identify terminated processes that may still have forensic artifacts in memory.
- ✗
windows.pslist
Why it's wrong here
windows.pslist lists currently active processes by walking the active process list. It does not include terminated processes because they are removed from the list upon termination. Thus, it would not reveal residual information from terminated processes, making it unsuitable for this scenario.
- ✗
windows.pstree
Why it's wrong here
windows.pstree displays processes in a tree structure based on parent-child relationships, which helps visualize process hierarchy but only includes active processes. It does not list terminated processes that may still have residual data. Therefore, it does not meet the analyst's need to find terminated processes in memory.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.