Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?

⚠ Common exam trap

The trap here is assuming that windows.malfind is always the best plugin for detecting code injection, but it only scans memory regions and does not enumerate threads or their start addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.threads

The windows.threads plugin enumerates threads within a process, showing start addresses that can be compared against known module ranges. Injected threads often have start addresses in unbacked memory, making this plugin ideal for detecting code injection. The other plugins focus on memory regions, handles, or loaded modules, none of which provide thread-level detail needed to identify an injected thread.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.dlllist

    Why it's wrong here

    windows.dlllist lists loaded DLLs and their base addresses for a process. It can reveal suspicious DLLs but does not enumerate threads or their start addresses. Since the analyst needs to examine threads specifically to detect injection, this plugin does not provide the required information and is therefore incorrect.

  • ✗

    windows.handles

    Why it's wrong here

    windows.handles enumerates open handles to objects such as files, registry keys, and mutexes for a process. While useful for understanding a process's resource usage, it does not provide information about threads or their start addresses. This plugin would not help identify injected threads, so it is not suitable for this scenario.

  • ✓

    windows.threads

    Why this is correct

    windows.threads lists all threads for a given process, including thread IDs, start addresses, and stack information. This allows an analyst to identify threads whose start addresses fall outside the normal module range, which is a strong indicator of code injection. It directly addresses the requirement to examine threads and their start addresses in volatile memory, making it the correct choice.

  • ✗

    windows.malfind

    Why it's wrong here

    windows.malfind scans process memory for hidden or injected code by looking for memory regions with unusual permissions, such as PAGE_EXECUTE_READWRITE, and missing mapped files. However, it does not enumerate threads or their start addresses. While it can indicate injection, it does not provide the thread-level detail needed to identify a specific injected thread. Therefore, it is not the best plugin for this scenario.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.