Courseiva

GCFA Introduction to Memory Forensics Practice Question

A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?

⚠ Common exam trap

The trap here is assuming that terminated processes are completely removed from memory, but their structures can linger until overwritten, which psscan can detect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.psscan

The windows.psscan plugin scans physical memory for process objects, which allows it to find processes that have been terminated but whose structures have not been overwritten. This is useful for identifying residual evidence from terminated processes. In contrast, pslist and pstree only show active processes, and cmdline provides arguments for active processes. Therefore, psscan is the correct choice for finding terminated processes in a memory dump.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.cmdline

    Why it's wrong here

    windows.cmdline displays command-line arguments for active processes, which can provide context but does not list terminated processes. It relies on active process structures and would not show residual information from terminated processes. Hence, it is not the appropriate plugin for this task.

  • ✓

    windows.psscan

    Why this is correct

    windows.psscan scans physical memory for process objects, including those that have been terminated but not yet overwritten. It can find residual process structures that are no longer in the active process list. This makes it the correct plugin to identify terminated processes that may still have forensic artifacts in memory.

  • ✗

    windows.pslist

    Why it's wrong here

    windows.pslist lists currently active processes by walking the active process list. It does not include terminated processes because they are removed from the list upon termination. Thus, it would not reveal residual information from terminated processes, making it unsuitable for this scenario.

  • ✗

    windows.pstree

    Why it's wrong here

    windows.pstree displays processes in a tree structure based on parent-child relationships, which helps visualize process hierarchy but only includes active processes. It does not list terminated processes that may still have residual data. Therefore, it does not meet the analyst's need to find terminated processes in memory.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.