GCFA · domain
Introduction to Memory Forensics
This domain covers acquiring and interpreting Windows memory images with Volatility 3, focusing on detecting fileless malware, hidden or unlinked processes, and network artifacts from terminated processes. Questions present realistic incident scenarios and require selecting the correct plugin, interpreting its output, and drawing defensible forensic conclusions from memory-resident evidence.
Focused practice
Practice Introduction to Memory Forensics questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Introduction to Memory Forensics
A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
Running windows.malfind to locate injected or suspicious executable memory regions in a process
Using windows.psscan to find processes unlinked from the active process list
Correlating windows.netscan connections with processes absent from windows.pslist
Understanding WinPmem acquisition and what a full physical memory image contains
Watch out for
Common Introduction to Memory Forensics exam traps
- ▸Assuming windows.pslist shows all processes; rootkits can unlink processes, so windows.psscan is needed to reveal hidden ones
- ▸Treating any malfind hit as confirmed malware; legitimate injected or packed code can also appear, so corroborate with other artifacts
- ▸Concluding a network connection is inactive because its process is missing from pslist, when the process may simply be terminated or hidden
Question index
All Introduction to Memory Forensics questions (53)
Click any question to see the full explanation, or start a practice session above.
Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?
Easy2A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?
Hard3Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?
Medium4You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)
Medium5A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)
Medium6An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?
Medium7When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?
Medium8In the context of memory forensics, what does the term 'Page File' represent in a crash dump?
Hard9An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?
Medium10An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?
Medium11A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?
Easy12An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?
Hard13An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)
Hard14A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?
Medium15When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?
Medium16An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?
Medium17During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?
Medium18A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)
Hard19An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?
Medium20In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?
Easy21A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)
Hard22During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?
Medium23A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?
Easy24You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?
Easy25During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?
Easy26When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?
Hard27Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?
Hard28An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?
Hard29A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?
Easy30A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?
Easy31An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?
Medium32An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?
Medium33A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?
Easy34Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?
Medium35Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?
Medium36A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)
Hard37You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?
Medium38An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?
Hard39A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)
Hard40An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?
Hard41A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?
Hard42When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?
Hard43Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?
Hard44During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?
Medium45When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?
Medium46You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?
Medium47Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?
Hard48Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?
Hard49You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?
Medium50An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?
Medium51During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?
Hard52Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?
Medium53Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?
MediumOther domains
All GCFA exam domains
Frequently asked questions
- What does the Introduction to Memory Forensics domain cover on the GCFA exam?
- A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
- How many questions are in this domain?
- This page lists all 53 Introduction to Memory Forensics questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Introduction to Memory Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.