GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?
⚠ Common exam trap
The trap here is assuming that a process listing plugin like pslist will reveal injected code, when in fact malfind is needed to inspect memory protections and thread start addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.malfind
The malfind plugin is designed to detect hidden or injected code in memory by identifying memory regions that are both writable and executable and that lack a corresponding file on disk. It also reports the start address of threads within those regions. This makes it the correct choice for finding threads that start outside of legitimate modules, which is a common indicator of process injection or fileless malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.pslist
Why it's wrong here
The pslist plugin enumerates active processes by walking the doubly linked list of EPROCESS structures. It provides process names, PIDs, and parent PIDs, but does not analyze thread start addresses or memory protections. It would not reveal injected code or threads starting outside of modules.
- ✗
windows.cmdline
Why it's wrong here
The cmdline plugin extracts command-line arguments for processes by reading the Process Environment Block (PEB). It is valuable for understanding how a process was launched but does not analyze thread start addresses or memory permissions. It would not identify threads starting outside legitimate modules.
- ✗
windows.netscan
Why it's wrong here
The netscan plugin scans for network artifacts such as TCP connections and listening ports by traversing pool allocations. While useful for identifying command-and-control connections, it does not inspect thread start addresses or memory regions for injected code. It is not suited for detecting fileless malware based on thread origins.
- ✓
windows.malfind
Why this is correct
The malfind plugin scans process memory for regions that are both executable and writable, and that do not map to a file on disk. It then displays the start address of threads within those regions, which is a strong indicator of injected code. This directly addresses the requirement to find threads starting outside legitimate modules.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.