GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?
⚠ Common exam trap
The trap here is assuming that windows.malfind is always the best plugin for detecting code injection, but it only scans memory regions and does not enumerate threads or their start addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.threads
The windows.threads plugin enumerates threads within a process, showing start addresses that can be compared against known module ranges. Injected threads often have start addresses in unbacked memory, making this plugin ideal for detecting code injection. The other plugins focus on memory regions, handles, or loaded modules, none of which provide thread-level detail needed to identify an injected thread.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.dlllist
Why it's wrong here
windows.dlllist lists loaded DLLs and their base addresses for a process. It can reveal suspicious DLLs but does not enumerate threads or their start addresses. Since the analyst needs to examine threads specifically to detect injection, this plugin does not provide the required information and is therefore incorrect.
- ✗
windows.handles
Why it's wrong here
windows.handles enumerates open handles to objects such as files, registry keys, and mutexes for a process. While useful for understanding a process's resource usage, it does not provide information about threads or their start addresses. This plugin would not help identify injected threads, so it is not suitable for this scenario.
- ✓
windows.threads
Why this is correct
windows.threads lists all threads for a given process, including thread IDs, start addresses, and stack information. This allows an analyst to identify threads whose start addresses fall outside the normal module range, which is a strong indicator of code injection. It directly addresses the requirement to examine threads and their start addresses in volatile memory, making it the correct choice.
- ✗
windows.malfind
Why it's wrong here
windows.malfind scans process memory for hidden or injected code by looking for memory regions with unusual permissions, such as PAGE_EXECUTE_READWRITE, and missing mapped files. However, it does not enumerate threads or their start addresses. While it can indicate injection, it does not provide the thread-level detail needed to identify a specific injected thread. Therefore, it is not the best plugin for this scenario.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.