GCFA Introduction to Memory Forensics Practice Question
An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?
⚠ Common exam trap
The trap here is conflating different kernel hooking techniques, such as SSDT hooking versus IRP hooking or callback manipulation, and selecting a plugin that targets the wrong structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.ssdt
The windows.ssdt plugin specifically parses the System Service Dispatch Table and compares each service routine pointer to the expected function address within the owning kernel module. Discrepancies indicate hooks, often used by rootkits to intercept system calls. The other plugins focus on callbacks, IRP handlers, or device trees, none of which directly analyze the SSDT for hooked entries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.driverirp
Why it's wrong here
windows.driverirp examines driver IRP (I/O Request Packet) handlers to detect hooked major functions. It focuses on driver dispatch tables, not the SSDT. While IRP hooking is a rootkit technique, it is distinct from SSDT hooking. Therefore, this plugin would not reveal SSDT hooks and is not the correct answer for this scenario.
- ✗
windows.devicetree
Why it's wrong here
windows.devicetree displays the device tree and driver objects associated with devices. It does not inspect the SSDT or system service routines. Although device tree anomalies can indicate rootkits, this plugin is not designed to detect SSDT hooks. Thus, it is not the appropriate tool for this specific analysis.
- ✓
windows.ssdt
Why this is correct
windows.ssdt parses the System Service Dispatch Table and compares each entry to the expected function based on the kernel module's export table, flagging entries that point outside the owning module. This directly detects SSDT hooks used by rootkits. It is the correct plugin for identifying hooked system service functions in this scenario.
- ✗
windows.callbacks
Why it's wrong here
windows.callbacks enumerates kernel callback routines registered by drivers, such as process creation, thread creation, and image load notifications. While rootkits can abuse callbacks, this plugin does not analyze the SSDT or detect function pointer hooks. It is useful for finding malicious callbacks but does not address SSDT hooking, so it is not the correct choice here.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.