Courseiva

GCFA Introduction to Memory Forensics Practice Question

An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?

⚠ Common exam trap

The trap here is concluding that a process found only by a pool scan must be a false positive or a terminated process, when the pattern is actually the expected signature of deliberate unlinking from the active process list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process object was unlinked from the active process list to hide it from standard enumeration.

When a process is missing from the active process list but its object is still discoverable by scanning pool memory, the most likely explanation is that the list entry was removed to conceal the process. This is the classic signature of DKOM-based rootkit hiding, because the object remains allocated and its pointers are intact even though it is no longer linked into the list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The process object was unlinked from the active process list to hide it from standard enumeration.

    Why this is correct

    A process that is missing from the active process list but still discoverable by a pool scan indicates that its list entry was removed, a technique known as DKOM. This is a hallmark of rootkit activity, because legitimate processes are not unlinked from the active list while they are running, and the pool scan finds the object because the structure itself remains allocated.

  • ✗

    The process was terminated before the memory image was captured, so only residual pool data remains.

    Why it's wrong here

    If the process had simply terminated, the pool scan would typically find a process object with an exit time set and no active threads. The fact that the process is absent from the active list but present in a pool scan is more consistent with deliberate unlinking than with normal termination, which would also remove the object from the active list but leave clear exit artifacts.

  • ✗

    The pool scan plugin produced a false positive by matching a freed process object that has not yet been reused.

    Why it's wrong here

    While pool scanners can encounter freed objects, a false positive is less likely when the object corresponds to a known suspicious process and has valid internal pointers. The combination of absence from the active list and presence in a pool scan is the expected signature of DKOM-based hiding, so attributing it solely to a false positive ignores the stronger explanation.

  • ✗

    The process is a legitimate system process that is intentionally excluded from the active process list by the kernel.

    Why it's wrong here

    Windows does not exclude legitimate processes from the active process list; all running processes are linked into it. A process absent from the list while its object remains in pool memory is anomalous and consistent with manipulation, not with normal kernel behavior, so this explanation does not fit the observed evidence.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.