GCFA Introduction to Memory Forensics Practice Question
An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?
⚠ Common exam trap
Candidates frequently suggest examining user-mode process lists or standard disk logs to detect kernel rootkits, missing the fact that kernel hooks operate below standard monitoring visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verifying the SSDT function pointers
Kernel hooks are a common rootkit tactic used to intercept system calls and hide malicious files, network connections, or processes. By performing integrity checks on the System Service Descriptor Table (SSDT) or the Interrupt Descriptor Table (IDT), an analyst can identify function pointers that point outside the expected range of the kernel's memory space, which is a clear indicator of malicious redirection and rootkit activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analyzing the process environment block (PEB)
Why it's wrong here
The PEB is a user-mode structure. Rootkits that hook kernel functions operate at a higher privilege level and reside in the kernel space. Analyzing the PEB will not reveal kernel-mode hooking, as the hooks exist within the operating system kernel's own internal function dispatch tables.
- ✓
Verifying the SSDT function pointers
Why this is correct
The SSDT is the dispatch table used by the kernel for system calls. Rootkits frequently overwrite these pointers to redirect execution to their own malicious code. Validating that all SSDT pointers reside within the legitimate kernel memory space is the standard method for detecting kernel-level hooks.
- ✗
Enumerating all running threads
Why it's wrong here
While thread enumeration is useful for finding hidden processes, it is not the correct technique for detecting kernel-level function hooking. Hooking involves redirecting code execution at the call site, not necessarily creating new threads, so this method would fail to identify the specific rootkit hooks.
- ✗
Scanning for file system changes in the MFT
Why it's wrong here
The MFT is a disk-based metadata structure. Kernel hooks exist in memory and do not necessarily involve changing files on the disk. Scanning the MFT will not detect active, volatile kernel-mode hooks, making this an ineffective strategy for identifying rootkits that operate solely within system memory.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.