Courseiva

GCFA · domain

Introduction to Memory Forensics

This domain covers acquiring and interpreting Windows memory images with Volatility 3, focusing on detecting fileless malware, hidden or unlinked processes, and network artifacts from terminated processes. Questions present realistic incident scenarios and require selecting the correct plugin, interpreting its output, and drawing defensible forensic conclusions from memory-resident evidence.

53 questions9 easy25 medium19 hard

Focused practice

Practice Introduction to Memory Forensics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Introduction to Memory Forensics

A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.

Running windows.malfind to locate injected or suspicious executable memory regions in a process

Using windows.psscan to find processes unlinked from the active process list

Correlating windows.netscan connections with processes absent from windows.pslist

Understanding WinPmem acquisition and what a full physical memory image contains

Watch out for

Common Introduction to Memory Forensics exam traps

  • ▸Assuming windows.pslist shows all processes; rootkits can unlink processes, so windows.psscan is needed to reveal hidden ones
  • ▸Treating any malfind hit as confirmed malware; legitimate injected or packed code can also appear, so corroborate with other artifacts
  • ▸Concluding a network connection is inactive because its process is missing from pslist, when the process may simply be terminated or hidden

Question index

All Introduction to Memory Forensics questions (53)

Click any question to see the full explanation, or start a practice session above.

1

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

Easy
2

A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?

Hard
3

Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?

Medium
4

You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)

Medium
5

A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)

Medium
6

An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?

Medium
7

When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?

Medium
8

In the context of memory forensics, what does the term 'Page File' represent in a crash dump?

Hard
9

An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?

Medium
10

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

Medium
11

A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?

Easy
12

An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?

Hard
13

An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)

Hard
14

A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?

Medium
15

When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?

Medium
16

An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?

Medium
17

During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?

Medium
18

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)

Hard
19

An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?

Medium
20

In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?

Easy
21

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)

Hard
22

During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?

Medium
23

A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?

Easy
24

You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?

Easy
25

During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?

Easy
26

When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?

Hard
27

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

Hard
28

An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?

Hard
29

A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?

Easy
30

A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?

Easy
31

An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?

Medium
32

An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?

Medium
33

A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?

Easy
34

Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?

Medium
35

Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?

Medium
36

A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)

Hard
37

You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?

Medium
38

An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?

Hard
39

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

Hard
40

An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?

Hard
41

A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?

Hard
42

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

Hard
43

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Hard
44

During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?

Medium
45

When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?

Medium
46

You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?

Medium
47

Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?

Hard
48

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

Hard
49

You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?

Medium
50

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Medium
51

During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?

Hard
52

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

Medium
53

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

Medium

Frequently asked questions

What does the Introduction to Memory Forensics domain cover on the GCFA exam?
A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
How many questions are in this domain?
This page lists all 53 Introduction to Memory Forensics questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Introduction to Memory Forensics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcfa GIAC-GCFA introduction to memory forensics Practice Questions