GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?
⚠ Common exam trap
The trap here is assuming that a connection from a known legitimate process to an external IP on port 443 is automatically benign, or conversely, immediately malicious; both assumptions are premature without further investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the remote IP with threat intelligence feeds and examine the process memory for injected code or unusual strings.
When a network connection from a legitimate process like chrome.exe is observed, it is not inherently malicious. The analyst must gather more evidence. Correlating the remote IP with threat intelligence can indicate if it is known malicious. Examining the process memory for injected code or unusual strings can reveal if the process has been compromised. This combination provides a stronger basis for determining the nature of the connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the system's DNS cache for the remote IP to see if it resolves to a known domain, which would confirm whether the connection is benign.
Why it's wrong here
The DNS cache may not contain the IP if the connection was made directly by IP or if the cache was cleared. Even if a domain is found, it could be a malicious domain or a compromised legitimate domain. Relying solely on DNS cache is insufficient to determine if the connection is malicious; it is just one piece of the puzzle.
- ✗
Immediately block the remote IP at the firewall and terminate the chrome.exe process, as an established connection to an external IP on port 443 is highly suspicious.
Why it's wrong here
Port 443 is the standard port for HTTPS, and it is normal for browsers like Chrome to have established connections to external IPs. Blocking the IP and terminating the process without further investigation could disrupt legitimate user activity and potentially destroy evidence. This action is premature and not based on forensic analysis.
- ✓
Correlate the remote IP with threat intelligence feeds and examine the process memory for injected code or unusual strings.
Why this is correct
The connection is from a legitimate process (chrome.exe) to a remote IP on port 443, which is common for HTTPS traffic. However, malware can inject into legitimate processes or use them to communicate with command-and-control servers. Correlating the IP with threat intelligence and examining the process memory for anomalies (e.g., injected code, suspicious strings) is the logical next step to determine if the connection is malicious. This approach balances the need to investigate without assuming benign or malicious.
- ✗
Run 'vol.py -f memory.dmp windows.dlllist --pid 1234' to list all loaded DLLs and check for any unsigned or suspicious modules.
Why it's wrong here
While listing DLLs can reveal suspicious modules, it is not the most direct next step to determine if the specific network connection is malicious. The connection itself could be benign even if the process has some suspicious DLLs. The analyst should first focus on the remote endpoint and the process memory related to the connection. DLL analysis is useful but secondary.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.