Courseiva

GCFA Introduction to Memory Forensics Practice Question

An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?

⚠ Common exam trap

The trap here is conflating different kernel hooking techniques, such as SSDT hooking versus IRP hooking or callback manipulation, and selecting a plugin that targets the wrong structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.ssdt

The windows.ssdt plugin specifically parses the System Service Dispatch Table and compares each service routine pointer to the expected function address within the owning kernel module. Discrepancies indicate hooks, often used by rootkits to intercept system calls. The other plugins focus on callbacks, IRP handlers, or device trees, none of which directly analyze the SSDT for hooked entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.driverirp

    Why it's wrong here

    windows.driverirp examines driver IRP (I/O Request Packet) handlers to detect hooked major functions. It focuses on driver dispatch tables, not the SSDT. While IRP hooking is a rootkit technique, it is distinct from SSDT hooking. Therefore, this plugin would not reveal SSDT hooks and is not the correct answer for this scenario.

  • ✗

    windows.devicetree

    Why it's wrong here

    windows.devicetree displays the device tree and driver objects associated with devices. It does not inspect the SSDT or system service routines. Although device tree anomalies can indicate rootkits, this plugin is not designed to detect SSDT hooks. Thus, it is not the appropriate tool for this specific analysis.

  • ✓

    windows.ssdt

    Why this is correct

    windows.ssdt parses the System Service Dispatch Table and compares each entry to the expected function based on the kernel module's export table, flagging entries that point outside the owning module. This directly detects SSDT hooks used by rootkits. It is the correct plugin for identifying hooked system service functions in this scenario.

  • ✗

    windows.callbacks

    Why it's wrong here

    windows.callbacks enumerates kernel callback routines registered by drivers, such as process creation, thread creation, and image load notifications. While rootkits can abuse callbacks, this plugin does not analyze the SSDT or detect function pointer hooks. It is useful for finding malicious callbacks but does not address SSDT hooking, so it is not the correct choice here.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.