GCFA Enterprise Environment Incident Response Practice Question
An enterprise incident responder is analyzing a compromised Linux server. The attacker used a rootkit that hooks system calls to hide processes and files. Which forensic technique is most effective to detect the rootkit's presence and identify hidden processes?
⚠ Common exam trap
The trap here is relying solely on signature-based rootkit scanners, which may fail against custom rootkits, instead of using a direct comparison method that exposes kernel-level discrepancies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare the output of ps and /proc directory listings.
A system call hooking rootkit often intercepts system calls used by tools like ps, causing them to omit hidden processes. The /proc file system, however, is generated by the kernel and may still list all processes. By comparing the process list from ps with the directory entries in /proc, an investigator can identify processes that are present in /proc but missing from ps, indicating rootkit manipulation. This technique is a classic method for detecting user-mode rootkits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run chkrootkit and rkhunter to scan for known rootkit signatures.
Why it's wrong here
chkrootkit and rkhunter are signature-based tools that detect known rootkits. A custom or newly developed rootkit may not have signatures, so these tools could produce false negatives. While they are useful for initial triage, they are not reliable for detecting unknown rootkits. The scenario implies a custom rootkit, so a more direct method like comparing /proc and ps is needed.
- ✗
Inspect the output of netstat -tulpn for unusual listening ports.
Why it's wrong here
netstat -tulpn shows network connections and listening ports, which can reveal backdoors but does not directly detect hidden processes. A rootkit that hides processes may also hide network connections from netstat. Therefore, relying on netstat alone is insufficient. It does not provide a method to identify processes that are hidden from standard tools, which is the core challenge here.
- ✗
Use Volatility to analyze a memory dump for hidden processes.
Why it's wrong here
Volatility is a powerful memory forensics framework, but it requires a memory dump. Acquiring memory from a live Linux system can be complex and may alter the system state. Moreover, if the rootkit hooks system calls, it might also interfere with memory acquisition tools. While memory analysis is valuable, the direct comparison of /proc and ps is more immediate and less invasive for detecting hidden processes.
- ✓
Compare the output of ps and /proc directory listings.
Why this is correct
A system call hooking rootkit often manipulates the output of tools like ps by intercepting system calls. However, the /proc file system is maintained by the kernel and may still contain entries for hidden processes. Comparing ps output with the contents of /proc can reveal discrepancies where processes exist in /proc but are not shown by ps, indicating rootkit activity.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.