Courseiva

GCFA Introduction to Memory Forensics Practice Question

An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?

⚠ Common exam trap

Many exam-takers confuse module listing with driver scanning, since both relate to kernel code but produce different evidence sets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.modules

windows.modules enumerates loaded kernel modules by traversing PsLoadedModuleList, yielding names, base addresses, and sizes suitable for baseline comparison. The other plugins target different artifacts: driverscan finds driver objects via pool scanning, svcscan lists services, and psscan recovers process objects. Only windows.modules directly satisfies the stated requirement on a Windows memory image.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.modules

    Why this is correct

    windows.modules parses the kernel's PsLoadedModuleList to enumerate loaded kernel drivers and modules, reporting their names, base addresses, and sizes. This directly supports building a baseline comparison for rootkit detection. The plugin works on Windows memory images and is the standard Volatility 3 replacement for the legacy Volatility 2 modlist plugin.

  • ✗

    windows.driverscan

    Why it's wrong here

    windows.driverscan scans memory for pool tags associated with driver objects rather than walking the loaded-module list. While it can reveal drivers missing from the module list, it does not produce a clean baseline listing of loaded kernel modules with their base addresses and sizes in the way the analyst needs for a direct comparison.

  • ✗

    windows.psscan

    Why it's wrong here

    windows.psscan scans for process objects in memory and is used to detect hidden processes. It has no relationship to kernel module enumeration. Running it would not produce a list of loaded kernel modules, base addresses, or sizes, so it cannot fulfill the analyst's requirement to compare against a known-good baseline.

  • ✗

    windows.svcscan

    Why it's wrong here

    windows.svcscan enumerates Windows services by walking the service record list in the registry, not kernel modules. Services and kernel drivers are related but not identical; many kernel modules are not services. This plugin would not provide the requested list of loaded kernel modules with base addresses and sizes.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.