GCFA Introduction to Memory Forensics Practice Question
An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?
⚠ Common exam trap
Students often assume standard process listing plugins will uncover all running programs, forgetting that sophisticated rootkits routinely unlink EPROCESS structures from active lists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware executed direct kernel object manipulation to remove the process entries from the active process doubly-linked list.
Standard process enumeration in Volatility relies on traversing the ActiveProcessLinks doubly-linked list rooted in the PsActiveProcessHead pointer. Advanced malware frequently unlinks EPROCESS structures from this list via direct kernel object manipulation to evade standard task manager visibility. Analysts must utilize kernel pool scanning plugins like pslist alternatives to recover these hidden entries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The memory acquisition tool utilized an unprivileged user-mode API that restricted kernel visibility.
Why it's wrong here
User-mode acquisition tools inherently struggle with full physical memory access, but kernel-level drivers bypass this limitation entirely by executing at ring 0. The missing processes stem from malicious structural manipulation rather than acquisition privilege boundaries.
- ✓
The malware executed direct kernel object manipulation to remove the process entries from the active process doubly-linked list.
Why this is correct
DKOM lets malware unlink an EPROCESS entry from the active process doubly-linked list, so Volatility 3's list-walk traversal cannot reach it. The processes remain resident in memory, which is why the stem's aggressive kernel driver acquisition still captured them but standard enumeration missed them.
- ✗
The operating system automatically paged the missing process control blocks out to the swap file during memory dumping.
Why it's wrong here
Physical memory acquisition captures the entire RAM contents, and active system processes are pinned in physical memory pages rather than being paged out to disk. Paging limitations do not account for systematic structural disappearance during forensic capture.
- ✗
Volatility 3 requires an outdated symbol table to correctly resolve the exact offsets of the Windows 10 kernel structures.
Why it's wrong here
Volatility 3 ships current symbol tables, and missing processes stem from the acquisition tool unlinking entries from the ActiveProcessLinks list, not from offset resolution failures. It is tempting because symbol mismatches do cause analysis errors, and supplying a matching symbol table would be correct when profiling an unfamiliar or patched kernel build.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.