Courseiva

GCFA Introduction to Memory Forensics Practice Question

An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?

⚠ Common exam trap

The trap here is assuming that Volatility 2 plugin names like windows.netstat carry over to Volatility 3, when in fact Volatility 3 uses different plugin names and architectures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.netscan

In Volatility 3, the windows.netscan plugin is designed to scan memory for network connection structures, providing details such as local and remote addresses, ports, and owning process IDs. It works by pool tag scanning, which can uncover connections even if they are not in the active list. The other options are either Volatility 2 plugins or non-existent, making windows.netscan the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.sockets

    Why it's wrong here

    windows.sockets is another Volatility 2 plugin that enumerates socket objects. It is not part of the standard Volatility 3 plugin set for network connection enumeration. While it can provide socket information, it does not directly list connections with process names and ports as required. Thus, it is not the correct choice for this Volatility 3 scenario.

  • ✗

    windows.netstat

    Why it's wrong here

    windows.netstat is a Volatility 2 plugin that lists network connections by traversing the active connection lists. In Volatility 3, this functionality is replaced by windows.netscan, which uses pool tag scanning for more comprehensive results. Therefore, windows.netstat is not the correct plugin for Volatility 3 and may not be available or may produce limited output.

  • ✗

    windows.connections

    Why it's wrong here

    windows.connections is not a standard Volatility 3 plugin. Volatility 3 uses windows.netscan for network connection enumeration. This option is a distractor that sounds plausible but does not exist in the Volatility 3 framework. Therefore, it cannot be used to list active network connections from a memory image.

  • ✓

    windows.netscan

    Why this is correct

    windows.netscan scans for network connection structures in memory, including TCP and UDP endpoints, and associates them with process IDs. It can reveal active and recently closed connections, making it ideal for identifying network activity from a memory image. This directly fulfills the requirement to list active network connections with process context.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.