GCFA Introduction to Memory Forensics Practice Question
An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?
⚠ Common exam trap
Many exam-takers confuse module listing with driver scanning, since both relate to kernel code but produce different evidence sets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.modules
windows.modules enumerates loaded kernel modules by traversing PsLoadedModuleList, yielding names, base addresses, and sizes suitable for baseline comparison. The other plugins target different artifacts: driverscan finds driver objects via pool scanning, svcscan lists services, and psscan recovers process objects. Only windows.modules directly satisfies the stated requirement on a Windows memory image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
windows.modules
Why this is correct
windows.modules parses the kernel's PsLoadedModuleList to enumerate loaded kernel drivers and modules, reporting their names, base addresses, and sizes. This directly supports building a baseline comparison for rootkit detection. The plugin works on Windows memory images and is the standard Volatility 3 replacement for the legacy Volatility 2 modlist plugin.
- ✗
windows.driverscan
Why it's wrong here
windows.driverscan scans memory for pool tags associated with driver objects rather than walking the loaded-module list. While it can reveal drivers missing from the module list, it does not produce a clean baseline listing of loaded kernel modules with their base addresses and sizes in the way the analyst needs for a direct comparison.
- ✗
windows.psscan
Why it's wrong here
windows.psscan scans for process objects in memory and is used to detect hidden processes. It has no relationship to kernel module enumeration. Running it would not produce a list of loaded kernel modules, base addresses, or sizes, so it cannot fulfill the analyst's requirement to compare against a known-good baseline.
- ✗
windows.svcscan
Why it's wrong here
windows.svcscan enumerates Windows services by walking the service record list in the registry, not kernel modules. Services and kernel drivers are related but not identical; many kernel modules are not services. This plugin would not provide the requested list of loaded kernel modules with base addresses and sizes.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.