Courseiva

GCFA Introduction to Memory Forensics Practice Question

An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?

⚠ Common exam trap

The trap here is assuming that the modules plugin provides a complete inventory of loaded kernel drivers, when a rootkit can unlink a driver from the module list while leaving its code and objects intact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.driverscan

A driver unlinked from PsLoadedModuleList will not appear in the modules plugin output, but its DRIVER_OBJECT may still reside in pool memory. The driverscan plugin locates these objects by scanning pool memory, making it the appropriate cross-check for detecting hidden or unlinked kernel drivers in the image.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.callbacks

    Why it's wrong here

    windows.callbacks enumerates registered kernel notification routines such as process, thread, and image load callbacks. It is useful for spotting malicious callback registration but does not scan for DRIVER_OBJECT structures, so it will not reveal a driver that has been removed from the loaded module list and hidden from normal enumeration.

  • ✗

    windows.svcscan

    Why it's wrong here

    windows.svcscan enumerates Windows services by walking the service record list in the registry and correlating them with service processes. It reports service configuration and state but does not parse kernel DRIVER_OBJECT structures, so it cannot detect a driver that has been unlinked from the kernel module list while its code remains resident.

  • ✗

    windows.ldrmodules

    Why it's wrong here

    windows.ldrmodules compares the three user-mode loader lists (InLoad, InInit, InMem) within a process to detect unlinked DLLs. It operates in user-mode address space and does not enumerate kernel drivers, so it cannot identify a kernel driver that has been unlinked from the loaded module list while remaining resident.

  • ✓

    windows.driverscan

    Why this is correct

    windows.driverscan scans pool memory for DRIVER_OBJECT structures rather than walking the linked list of loaded modules, so it can surface drivers that have been unlinked from PsLoadedModuleList but whose objects remain allocated. This directly addresses the requirement of finding drivers missing from the on-disk module list and provides a cross-check against the modules plugin output.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.