Courseiva

CCNA Introduction to Memory Forensics Questions

53 questions · Introduction to Memory Forensics · All types, answers revealed

1
MCQeasy

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

A.The Master File Table (MFT)
B.The Process Environment Block (PEB)
C.The Registry Hive files
D.The System Service Descriptor Table (SSDT)
AnswerB

The PEB is a user-mode data structure that contains essential information about a process, including the full command line used to launch it. Accessing this via memory forensics allows analysts to recover the exact execution path and any arguments passed to the malicious process, which are often missing.

Why this answer

Reconstructing command-line arguments is essential for understanding the specific intent of a malicious executable. The Process Environment Block (PEB) contains the command line string passed to a process at the time of its creation. By extracting this structure from memory, an analyst can reveal hidden parameters, remote IP addresses, or command flags that the malware author attempted to hide from the visual process list, providing critical context for the investigation.

Exam trap

Candidates often look for the command line in the EPROCESS structure itself, not realizing that the kernel does not store the full command-line string there, but rather points to the PEB.

2
MCQhard

A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?

A.Import Address Table (IAT) hooking, where the rootkit modifies the IAT of user-mode processes to redirect API calls to its own code.
B.SSDT hooking, where the rootkit replaces the function pointers in the SSDT to redirect system calls to its own malicious functions.
C.Inline hooking of the SSDT functions, where the rootkit overwrites the first bytes of the legitimate functions with a jump to its own code.
D.DKOM on the SSDT, where the rootkit unlinks the SSDT from the kernel's list of service tables to hide its modifications.
AnswerB

SSDT hooking involves modifying the SSDT so that system service calls are redirected to malicious code. The SSDT normally contains pointers to legitimate kernel functions. If entries point to an unsigned module not in the loaded module list, it indicates that the table has been tampered with. This is a classic rootkit technique to intercept system calls and hide its activities, and it matches the observed evidence.

Why this answer

The SSDT contains pointers to kernel functions for system services. If entries point to an unsigned module not in the loaded module list, it indicates that the SSDT has been hooked—modified to redirect system calls to malicious code. This is a classic rootkit technique to intercept and manipulate system calls, allowing the rootkit to hide its presence and activities.

Inline hooking and IAT hooking affect different structures, and DKOM does not apply to the SSDT in this manner.

Exam trap

The trap here is confusing SSDT hooking with inline hooking; SSDT hooking changes the function pointers in the table, while inline hooking patches the function code itself, leaving the table intact.

3
MCQmedium

Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?

A.It stores the process command line arguments
B.It is used for memory page table translations
C.It contains metadata like reference counts and types
D.It provides a mapping for disk-based sectors
AnswerC

The object header is an essential kernel data structure that tracks reference counts and object types. Forensic analysts use this header to understand how the kernel is managing an object, which can reveal information about the object's origin, its protection state, and its current status in memory.

Why this answer

The Object Header precedes the body of every object managed by the Windows kernel, such as processes, threads, or files. It contains critical metadata, including the object type, reference count, and security descriptor. For forensic analysts, this header provides vital information about the object's lifespan and permissions, which is crucial for identifying unauthorized access or tracking the lifecycle of malicious objects within the kernel's memory management system.

Exam trap

Candidates frequently mistake the Object Header for actual process execution code, missing its true function as a kernel metadata container tracking object lifespans and permissions.

4
Multi-Selectmedium

You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)

Select 2 answers
A.windows.modscan
B.windows.driverirp
C.windows.callbacks
D.windows.modules
E.windows.driverscan
AnswersA, E

windows.modscan scans kernel pool memory for module structures, which can reveal modules that have been unlinked from the active module list. This is exactly the technique needed to find a hidden driver that a rootkit has removed from PsLoadedModuleList. It can detect the malicious driver's residual metadata, making it a correct choice for this scenario.

Why this answer

To detect a driver that has been unlinked from the active module list, you need plugins that scan kernel pool memory for driver-related structures. windows.modscan finds module structures, and windows.driverscan finds driver objects. Together they can reveal a hidden driver that a rootkit has unlinked. The other plugins either list only active modules, focus on IRP hooking, or enumerate callbacks, none of which directly detect unlinked drivers.

Exam trap

The trap here is assuming that windows.modules will show all loaded drivers, but a rootkit can unlink its driver so that it no longer appears in that list.

5
Multi-Selectmedium

A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)

Select 2 answers
A.A memory region containing a PE header (MZ) that matches a known legitimate system DLL on disk.
B.A memory region with PAGE_EXECUTE_READWRITE protection that contains a MZ header but has no corresponding file path in the VAD.
C.A memory region with PAGE_READONLY protection that contains configuration data.
D.A memory region with PAGE_EXECUTE_READ protection that is backed by a signed Microsoft DLL.
E.A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk.
AnswersB, E

This combines multiple red flags: RWX permissions, an executable header, and no file backing. The absence of a file path in the VAD means the region is unbacked, which is highly suspicious. The MZ header indicates executable content, and RWX allows modification and execution. Together, these strongly suggest that malicious code was injected into the process's memory space, as legitimate modules are file-backed and typically not RWX.

Why this answer

Indicators of process injection include memory regions with PAGE_EXECUTE_READWRITE protection that are unbacked by a file on disk, especially when they contain executable headers like MZ. These characteristics suggest that code was injected directly into the process's address space, bypassing normal module loading. Legitimate code is usually backed by files and has more restrictive permissions.

Therefore, the combination of RWX permissions and lack of file backing is a key red flag.

Exam trap

The trap here is focusing solely on the presence of a PE header or executable permissions without considering file backing; legitimate modules are file-backed, so unbacked RWX regions with PE headers are the true indicators.

6
MCQmedium

An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?

A.windows.sockets
B.windows.netstat
C.windows.connections
D.windows.netscan
AnswerD

windows.netscan scans for network connection structures in memory, including TCP and UDP endpoints, and associates them with process IDs. It can reveal active and recently closed connections, making it ideal for identifying network activity from a memory image. This directly fulfills the requirement to list active network connections with process context.

Why this answer

In Volatility 3, the windows.netscan plugin is designed to scan memory for network connection structures, providing details such as local and remote addresses, ports, and owning process IDs. It works by pool tag scanning, which can uncover connections even if they are not in the active list. The other options are either Volatility 2 plugins or non-existent, making windows.netscan the correct choice.

Exam trap

The trap here is assuming that Volatility 2 plugin names like windows.netstat carry over to Volatility 3, when in fact Volatility 3 uses different plugin names and architectures.

7
MCQmedium

When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?

A.To ensure the memory image is encrypted correctly
B.To determine the correct offsets for kernel data structures
C.To increase the speed of the memory dumping process
D.To bypass the system's kernel-mode security drivers
AnswerB

Kernel structures are highly dependent on the specific OS version and kernel build. The profile tells the forensic tool the exact location and size of these structures, such as process lists and thread blocks, ensuring that the tool parses the memory image accurately without data misalignment errors.

Why this answer

Kernel data structures, such as the EPROCESS list or the KPCR, change in offset and size between different OS builds and service packs. If an incorrect profile is used, the analysis tool will misinterpret these structures, leading to incorrect process listing, failed memory mapping, or complete analysis failure. Using the correct profile ensures that the tool accurately maps the memory layout according to the specific kernel offsets of the target system.

Exam trap

Candidates often think the memory image itself contains all necessary structures. However, without the correct profile, the analysis tool cannot correctly interpret the kernel's memory layout and data offsets.

8
MCQhard

In the context of memory forensics, what does the term 'Page File' represent in a crash dump?

A.A reserved section of the CPU cache.
B.A file that stores inactive virtual memory.
C.A list of all allocated kernel drivers.
D.A log of all system process launches.
AnswerB

The page file acts as backing store for virtual memory pages that are not currently resident in physical RAM. Forensic analysis often requires examining the page file to recover data that was swapped out, which is common for inactive or long-running processes that hold evidence of malicious activity.

Why this answer

The page file is a disk-based extension of physical RAM. When a system performs a dump, it may contain data swapped from physical memory to the page file. Forensic analysts must understand this because critical evidence—such as decrypted payloads or old process data—might exist in the page file rather than the active physical RAM, requiring the analyst to reconstruct the virtual address space using both sources.

Exam trap

Candidates often confuse the page file with active physical RAM or volatile registry hives, missing its role as disk-based virtual memory storage.

9
MCQmedium

An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?

A.windows.callbacks
B.windows.svcscan
C.windows.ldrmodules
D.windows.driverscan
AnswerD

windows.driverscan scans pool memory for DRIVER_OBJECT structures rather than walking the linked list of loaded modules, so it can surface drivers that have been unlinked from PsLoadedModuleList but whose objects remain allocated. This directly addresses the requirement of finding drivers missing from the on-disk module list and provides a cross-check against the modules plugin output.

Why this answer

A driver unlinked from PsLoadedModuleList will not appear in the modules plugin output, but its DRIVER_OBJECT may still reside in pool memory. The driverscan plugin locates these objects by scanning pool memory, making it the appropriate cross-check for detecting hidden or unlinked kernel drivers in the image.

Exam trap

The trap here is assuming that the modules plugin provides a complete inventory of loaded kernel drivers, when a rootkit can unlink a driver from the module list while leaving its code and objects intact.

10
MCQmedium

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

A.The Master File Table (MFT) entry
B.The Thread Environment Block (TEB)
C.The process structures in memory
D.The System Service Descriptor Table (SSDT)
AnswerC

Process hollowing involves creating a legitimate process in a suspended state and replacing its memory contents. The operating system maintains the PEB for legacy application compatibility, but the VAD tree manages the actual memory ranges mapped to the process. Mismatches here are a hallmark of process injection.

Why this answer

Discrepancies between the PEB and the Virtual Address Descriptor (VAD) tree often indicate process hollowing or replacement. Malware frequently updates the PEB image path to masquerade as legitimate system services while the VAD tree reflects the actual memory mapping of the injected code. Identifying this mismatch is critical for uncovering stealthy code injection techniques that bypass simple process listing tools by hiding the true origin of the executable.

Exam trap

Test-takers often misattribute PEB and VAD tree discrepancies to simple file corruption or benign application updates rather than recognizing advanced process hollowing techniques.

11
MCQeasy

A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?

A.windows.netscan
B.windows.sockets
C.windows.netstat
D.windows.connections
AnswerA

The windows.netscan plugin scans for network artifacts in memory, including TCP and UDP endpoints, and associates them with the owning process. It is designed to work across Windows versions and provides details such as local and remote addresses, ports, and process IDs. This directly meets the examiner's requirement to identify active network connections and their responsible processes.

Why this answer

The windows.netscan plugin in Volatility 3 is specifically designed to scan memory for network connection structures and correlate them with owning processes. It provides a comprehensive view of active TCP and UDP endpoints, including local and remote addresses, ports, and process IDs. Other plugin names listed are either non-existent or less reliable, making windows.netscan the correct choice for this task.

Exam trap

The trap here is assuming that a plugin named windows.netstat, similar to the live netstat command, is the best choice, when in fact windows.netscan is the Volatility 3 standard for memory-based network artifact recovery.

12
MCQhard

An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?

A.Check the system event log for a service control manager entry indicating the driver was started.
B.Search for the driver's pool tags and compare them against the current loaded module list to identify remnants of an unloaded driver.
C.Examine the registry hives in memory for the driver's service key and confirm its start type.
D.Run windows.modules and check whether the driver appears in the output.
AnswerB

Unloaded drivers can leave pool allocations and pool tags in memory even after their module entry is removed. Searching for the driver's known pool tags and comparing against the current module list can reveal remnants indicating the driver was present earlier. This technique leverages memory artifacts that persist beyond the driver's active lifetime, providing evidence of prior loading.

Why this answer

Pool tags and residual pool allocations can persist after a driver unloads, so searching for a driver's known pool tags and comparing against the current module list can reveal that it was loaded earlier. The module list itself only shows current modules, registry keys show configuration, and event logs are not reliable for this purpose in memory forensics.

Exam trap

The trap here is relying on the current module list or registry configuration to answer a historical question about whether a driver was ever loaded.

13
Multi-Selecthard

An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)

Select 2 answers
A.The process's token has been modified to include SeDebugPrivilege.
B.The process's primary image memory region is not backed by the file on disk that its path indicates.
C.The process has a thread whose start address lies outside any legitimate loaded module.
D.The process has a working set larger than the system average.
E.The process has a large number of handles open to named pipes.
AnswersB, C

Process hollowing replaces the legitimate image with malicious code, so the in-memory image no longer matches the on-disk executable. Detecting a primary image region that is unbacked or whose contents differ from the file at the recorded path is a core indicator. This artifact alone is highly suggestive when combined with other anomalies.

Why this answer

Process hollowing unmaps or overwrites the original image and injects replacement code, so the primary image region loses its legitimate file backing and threads often start in unbacked memory. Observing both an unbacked primary image and a thread starting outside known modules forms a coherent, high-confidence pattern. Pipe handles, token privilege changes, and working set size are unrelated to the hollowing technique.

Exam trap

The trap here is treating any single anomaly as proof of hollowing, when the technique is best confirmed by combining image-backing and thread-start anomalies.

14
MCQmedium

A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?

A.The process is a legitimate service host that was terminated and its EPROCESS is lingering in pool memory before being freed.
B.The process is a child of a protected process and is intentionally excluded from the active process list by Windows security features.
C.The process is a zombie process that has been reaped by its parent but its EPROCESS remains in memory due to a handle leak.
D.The process is hidden from the active process list due to direct kernel object manipulation (DKOM) unlinking its EPROCESS from the PsActiveProcessHead list.
AnswerD

DKOM rootkits often unlink a malicious process's EPROCESS from the doubly linked list pointed to by PsActiveProcessHead, hiding it from tools that rely on that list. Pool scanning (psscan) traverses pool tags to find EPROCESS objects regardless of list membership, so it detects the hidden process. The absence of the process in pslist but presence in psscan is a classic indicator of DKOM-based process hiding.

Why this answer

The discrepancy between psscan and pslist where a process appears in pool scanning but not in the active list is a hallmark of DKOM-based process hiding. Rootkits unlink the EPROCESS from the active process list to evade detection by tools that walk that list. Pool scanning finds the structure directly in memory, revealing the hidden process.

This is a fundamental technique in memory forensics for detecting stealthy malware.

Exam trap

The trap here is assuming that a process missing from pslist but present in psscan is merely a terminated process, when the lack of an ExitTime and the rootkit context indicate deliberate DKOM unlinking.

15
MCQmedium

When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?

A.To identify all running processes.
B.To find the current thread context.
C.To map virtual addresses to physical pages.
D.To reset kernel-mode security policies.
AnswerB

The KPCR stores the pointer to the currently executing thread for a specific core. By locating the KPCR in memory, an analyst can determine exactly what the processor was executing at the time the dump was taken, which is crucial for analyzing live malware execution and suspicious kernel threads.

Why this answer

The KPCR is a structure containing critical processor-specific information, including the current thread and CPU state. It is vital for forensic analysts because it serves as the anchor for finding the current thread of execution on each core. Understanding the KPCR helps analysts reconstruct the execution context, which is essential for identifying which threads were running at the moment of capture, especially during complex multi-threaded attacks.

Exam trap

Candidates often confuse the KPCR with the EPROCESS structure, incorrectly assuming it tracks process-level metadata rather than the low-level processor state and current thread context required by the kernel.

16
MCQmedium

An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?

A.windows.netscan
B.windows.malfind
C.windows.pslist
D.windows.cmdline
AnswerB

windows.malfind scans for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk, which are typical of code injection. It helps identify injected code even when the process image is missing. This plugin is specifically designed to detect hidden or injected code in process memory, making it the correct choice for this scenario.

Why this answer

The windows.malfind plugin is designed to detect injected code by scanning for memory regions that are executable but not backed by a file on disk. In this scenario, the process's image path is missing, which is a red flag for injection. Malfind would reveal such anomalies, helping the analyst confirm the presence of injected code.

Other plugins like pslist, netscan, and cmdline do not perform this type of memory analysis.

Exam trap

The trap here is assuming that any plugin that lists processes or network connections can detect code injection, when only malfind specifically analyzes memory regions for suspicious characteristics.

17
MCQmedium

During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?

A.windows.psscan
B.windows.netscan
C.windows.pstree
D.windows.cmdline
AnswerA

windows.psscan scans physical memory for EPROCESS structures using pool tag scanning, which can reveal processes that are not linked in the active process list due to rootkit unlinking or other hiding techniques. This directly addresses the need to find hidden processes by comparing against windows.pslist. It is the correct plugin for detecting discrepancies that indicate process hiding.

Why this answer

windows.psscan uses pool tag scanning to locate EPROCESS structures in memory, which can uncover processes that have been unlinked from the active process list by rootkits or other hiding techniques. By comparing its output with windows.pslist, an analyst can identify discrepancies indicating hidden processes. The other plugins either rely on the active list or serve different purposes, such as command-line retrieval or network connection enumeration.

Exam trap

The trap here is assuming that windows.pstree, which shows parent-child relationships, would automatically reveal hidden processes, but it only displays processes already present in the active list.

18
Multi-Selecthard

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)

Select 2 answers
A.windows.handles
B.windows.netscan
C.windows.dlllist
D.windows.psscan
E.windows.pslist
AnswersD, E

windows.psscan scans physical memory for process objects by using pool tag scanning, which can find processes that are unlinked from the active process list. It is effective for detecting hidden processes because it does not rely on the operating system's linked list. This plugin is essential when a rootkit has unlinked a process to hide it.

Why this answer

To detect hidden processes, analysts compare the output of windows.pslist, which walks the active process list, with windows.psscan, which scans physical memory for process objects using pool tag scanning. Discrepancies where psscan finds processes not in pslist indicate hidden processes, often due to rootkit activity. The other plugins do not provide this comparison and are used for different forensic purposes.

Exam trap

The trap here is thinking that any plugin that lists processes can detect hidden ones, but only the combination of pslist and psscan reveals discrepancies caused by unlinking.

19
MCQmedium

An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?

A.Analyzing the process environment block (PEB)
B.Verifying the SSDT function pointers
C.Enumerating all running threads
D.Scanning for file system changes in the MFT
AnswerB

The SSDT is the dispatch table used by the kernel for system calls. Rootkits frequently overwrite these pointers to redirect execution to their own malicious code. Validating that all SSDT pointers reside within the legitimate kernel memory space is the standard method for detecting kernel-level hooks.

Why this answer

Kernel hooks are a common rootkit tactic used to intercept system calls and hide malicious files, network connections, or processes. By performing integrity checks on the System Service Descriptor Table (SSDT) or the Interrupt Descriptor Table (IDT), an analyst can identify function pointers that point outside the expected range of the kernel's memory space, which is a clear indicator of malicious redirection and rootkit activity.

Exam trap

Candidates frequently suggest examining user-mode process lists or standard disk logs to detect kernel rootkits, missing the fact that kernel hooks operate below standard monitoring visibility.

20
MCQeasy

In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?

A.To store the process execution priority.
B.To map virtual memory ranges for a process.
C.To log all network connections made.
D.To secure the process against buffer overflows.
AnswerB

The VAD tree tracks all virtual memory allocations, providing the kernel with the necessary information to handle page faults and enforce memory access permissions. Forensic tools analyze the VAD tree to reconstruct the process memory map, which is necessary to identify injected code, unbacked regions, and suspicious memory attributes.

Why this answer

The VAD tree is a kernel structure used by the memory manager to keep track of the virtual memory ranges allocated to a process. It is essential for forensic analysts because it defines the memory map of a process, including which areas are executable, read-only, or writable. This structure is critical for identifying memory-resident threats that attempt to hide their presence by manipulating memory permissions to execute malicious code.

Exam trap

Candidates often confuse the VAD tree with the Page Table or physical memory structures, incorrectly attributing the mapping of virtual address spaces to lower-level hardware memory management components.

21
Multi-Selecthard

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)

Select 2 answers
A.The presence of a driver object with no corresponding file on disk in the drivers directory.
B.The SSDT is found to be writable in memory, whereas it should be read-only in a clean system.
C.The ntoskrnl.exe module in memory has a different hash than the known-good version from the same Windows build.
D.The KPCR (Kernel Processor Control Region) for each CPU shows a different value for the IDT base address.
E.The System Service Descriptor Table (SSDT) entries point to addresses outside the ntoskrnl.exe module.
AnswersB, E

In a clean Windows system, the SSDT is typically protected as read-only after initialization. If the SSDT is writable, it suggests that a rootkit has modified memory protections to allow hooking. This is a strong indicator of SSDT hooking because the rootkit must disable write protection to alter the table.

Why this answer

SSDT hooking involves redirecting system service calls by modifying the SSDT, which normally points to functions within ntoskrnl.exe. Two key indicators are SSDT entries pointing outside ntoskrnl.exe and the SSDT being writable when it should be read-only. Other artifacts like missing driver files or IDT variations are not specific to SSDT hooking, and a modified kernel hash indicates patching rather than hooking.

Exam trap

The trap here is confusing general rootkit indicators with specific evidence of SSDT hooking, such as assuming any kernel modification or missing driver file proves SSDT manipulation.

22
MCQmedium

During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?

A.The connections are proof of a network-based attack and should be reported as a confirmed incident.
B.The connections indicate that the memory image is corrupted and should be reacquired.
C.The connections prove that a rootkit is hiding a running process from the process list.
D.The connections are likely residual artifacts from a terminated process, and the examiner should correlate timestamps and process IDs to confirm.
AnswerD

windows.netscan parses network structures that may persist after a process exits, especially if the process object has not been fully reclaimed. Residual connections from terminated processes are common and should be validated by correlating process IDs, timestamps, and related artifacts rather than immediately concluding malicious activity. This cautious correlation approach avoids false positives.

Why this answer

windows.netscan can surface network structures that outlive their owning process, so missing process entries alongside established connections often reflect terminated processes rather than hidden malware. Correlating process IDs, timestamps, and other artifacts is the proper next step. Claiming rootkit activity, image corruption, or a confirmed attack from this observation alone is premature and unsupported.

Exam trap

The trap here is assuming any mismatch between network connections and the process list indicates active hiding, when stale structures from exited processes are a common benign cause.

23
MCQeasy

A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?

A.windows.dlllist
B.windows.modules
C.windows.handles
D.windows.pslist
AnswerB

windows.modules scans the kernel module list and reports loaded kernel modules, including drivers and their base addresses. This directly supports comparing loaded modules against a known-good baseline to detect unauthorized drivers. It is the appropriate Volatility 3 plugin for enumerating kernel modules from a Windows memory image, making it the correct choice here.

Why this answer

The windows.modules plugin is designed to enumerate loaded kernel modules from a Windows memory image, providing a list of drivers and their base addresses. This is essential for comparing against a known-good baseline to identify unauthorized or malicious kernel modules. The other plugins target process lists, DLLs within processes, or handles, none of which directly provide a system-wide kernel module enumeration.

Exam trap

The trap here is confusing process-level DLL enumeration with kernel module enumeration, as both involve loaded code but operate at different privilege levels and require different plugins.

24
MCQeasy

You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?

A.windows.cmdline
B.windows.registry.hivelist
C.windows.pslist
D.windows.info
AnswerD

windows.info reads the kernel's version information and other basic system details directly from the memory image. It displays the major and minor version, build number, service pack, and architecture, which are essential for selecting the correct symbol table or profile. This plugin is specifically designed to provide OS identification from memory, making it the correct choice.

Why this answer

To identify the operating system version and service pack from a memory image, you need a plugin that reads kernel version data. windows.info extracts this directly from the kernel structures in memory, providing the build number and service pack level. The other plugins focus on registry hives, process listing, and command lines, none of which directly report the OS version in a concise manner.

Exam trap

The trap here is thinking that the registry hivelist will give you the OS version quickly, when in fact you would need to parse the registry separately and it is not a direct memory analysis plugin for OS identification.

25
MCQeasy

During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?

A.The KDBG structure, because it stores the list of logged-on user sessions and their SIDs.
B.The EPROCESS block for winlogon.exe, because it stores the Security Identifier (SID) of the interactive user.
C.The token object referenced by explorer.exe, because its user SID identifies the interactively logged-on account.
D.The PEB of lsass.exe, because it caches the credentials of the interactive user in plaintext.
AnswerC

Explorer.exe runs in the interactive user's context, and its primary token contains the user SID of that account. Parsing the token from explorer.exe's EPROCESS in memory reveals the interactive user. This is a standard technique in memory forensics for attributing activity to a specific logged-on user when no other session artifacts are available.

Why this answer

The interactive user's identity is tied to the token of a process running in that user's session, such as explorer.exe. Extracting the token SID from explorer.exe's EPROCESS in the memory image confirms which account was interactively logged on. Other structures like KDBG or winlogon's EPROCESS do not directly hold the interactive user SID, making them unsuitable for this specific attribution.

Exam trap

The trap here is assuming that winlogon.exe or lsass.exe directly store the interactive user's SID in their process structures, when the reliable source is the token of a user-context process like explorer.exe.

26
Multi-Selecthard

When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?

Select 3 answers
A.Memory segments marked as PAGE_EXECUTE_READWRITE
B.The presence of standard DLLs in the loading list
C.Memory regions that are executable but not file-backed
D.The thread environment block (TEB) memory region
E.Discrepancy between disk and memory on-disk binaries
AnswersA, C, E

Memory pages with Read, Write, and Execute (RWX) permissions are rare in legitimate software. These permissions are often a requirement for self-modifying code or injected payloads, making them a primary target for finding malicious code that needs to both write its payload and subsequently execute it.

Why this answer

Code injection often involves modifying existing memory segments or creating new ones with abnormal permissions. Analysts must look for areas of memory that are marked as executable but do not map to a file on disk (private memory), detect hooks in common system libraries, or identify discrepancies between memory-resident code and the original binary on disk. These indicators are classic signs that a process has been tampered with to execute malicious logic.

Exam trap

Candidates often focus only on the MZ header, ignoring that modern fileless malware can hide by hooking system calls or modifying existing legitimate memory regions without necessarily needing a new PE header.

27
MCQhard

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

A.The PID 1240 is assigned to svchost.exe
B.The existence of two svchost.exe processes
C.The parent-child relationship of svchost.exe and explorer.exe
D.The PID of explorer.exe is higher than svchost.exe
AnswerC

Explorer.exe is typically launched by userinit.exe during the login sequence. When svchost.exe, a process intended for background system services, spawns the shell, it indicates that the system has been compromised. This violation of established process lineage is a primary indicator of process injection or hollowing.

Why this answer

The exhibit shows explorer.exe being spawned by svchost.exe. In a standard Windows environment, explorer.exe is spawned by userinit.exe, which in turn is spawned by winlogon.exe. A service host process (svchost.exe) spawning the Windows shell is highly anomalous behavior.

This pattern suggests an injection or a process replacement attack where a malicious service has hijacked the shell or launched a secondary GUI interface for persistent command and control.

Exam trap

Candidates often misidentify legitimate svchost.exe behavior by assuming any child process of svchost.exe is malicious, failing to recognize that specific services like taskhostw.exe are legitimate children of svchost.exe.

28
MCQhard

An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?

A.The process object was unlinked from the active process list to hide it from standard enumeration.
B.The process was terminated before the memory image was captured, so only residual pool data remains.
C.The pool scan plugin produced a false positive by matching a freed process object that has not yet been reused.
D.The process is a legitimate system process that is intentionally excluded from the active process list by the kernel.
AnswerA

A process that is missing from the active process list but still discoverable by a pool scan indicates that its list entry was removed, a technique known as DKOM. This is a hallmark of rootkit activity, because legitimate processes are not unlinked from the active list while they are running, and the pool scan finds the object because the structure itself remains allocated.

Why this answer

When a process is missing from the active process list but its object is still discoverable by scanning pool memory, the most likely explanation is that the list entry was removed to conceal the process. This is the classic signature of DKOM-based rootkit hiding, because the object remains allocated and its pointers are intact even though it is no longer linked into the list.

Exam trap

The trap here is concluding that a process found only by a pool scan must be a false positive or a terminated process, when the pattern is actually the expected signature of deliberate unlinking from the active process list.

29
MCQeasy

A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?

A.Compute a cryptographic hash of the memory image immediately after acquisition and record it in the case notes.
B.Compress the memory image with a proprietary format to reduce its size before hashing.
C.Open the memory image in a hex editor to verify its contents before storing it.
D.Store the memory image on the same server from which it was captured to preserve chain of custody.
AnswerA

Hashing the image right after acquisition creates a verifiable baseline for integrity. Any later comparison can confirm the image is unchanged. This is a fundamental forensic practice that supports admissibility and defensibility, and it applies directly to memory images just as it does to disk images, ensuring the evidence can be trusted throughout the investigation.

Why this answer

Cryptographic hashing immediately after acquisition establishes a verifiable integrity baseline for the memory image. Storing the image on the source host, using proprietary compression before hashing, or inspecting it in a hex editor does not provide that assurance and may introduce risk. Hashing is the standard, defensible method to demonstrate the image has not been altered.

Exam trap

The trap here is equating any handling step with integrity preservation, when only cryptographic hashing provides a verifiable baseline.

30
MCQeasy

A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?

A.windows.svcscan
B.windows.modules
C.windows.dlllist
D.windows.driverscan
AnswerB

The windows.modules plugin parses the kernel's module list (PsLoadedModuleList) and outputs each loaded driver, including its base address, size, and full path. This directly satisfies the requirement to enumerate kernel modules from a memory image and compare against the OS-reported list for discrepancies.

Why this answer

The windows.modules plugin is designed to walk the kernel's loaded module list (PsLoadedModuleList) and display each module's name, base address, size, and path. This directly supports the analyst's goal of enumerating kernel modules from a memory image and comparing them against the operating system's reported list to identify discrepancies.

Exam trap

The trap here is confusing kernel module enumeration with driver object scanning or user-mode DLL listing, which serve different forensic purposes.

31
MCQmedium

An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?

A.The memory acquisition tool utilized an unprivileged user-mode API that restricted kernel visibility.
B.The malware executed direct kernel object manipulation to remove the process entries from the active process doubly-linked list.
C.The operating system automatically paged the missing process control blocks out to the swap file during memory dumping.
D.Volatility 3 requires an outdated symbol table to correctly resolve the exact offsets of the Windows 10 kernel structures.
AnswerB

DKOM lets malware unlink an EPROCESS entry from the active process doubly-linked list, so Volatility 3's list-walk traversal cannot reach it. The processes remain resident in memory, which is why the stem's aggressive kernel driver acquisition still captured them but standard enumeration missed them.

Why this answer

Standard process enumeration in Volatility relies on traversing the ActiveProcessLinks doubly-linked list rooted in the PsActiveProcessHead pointer. Advanced malware frequently unlinks EPROCESS structures from this list via direct kernel object manipulation to evade standard task manager visibility. Analysts must utilize kernel pool scanning plugins like pslist alternatives to recover these hidden entries.

Exam trap

Students often assume standard process listing plugins will uncover all running programs, forgetting that sophisticated rootkits routinely unlink EPROCESS structures from active lists.

32
MCQmedium

An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?

A.windows.modules
B.windows.driverscan
C.windows.psscan
D.windows.svcscan
AnswerA

windows.modules parses the kernel's PsLoadedModuleList to enumerate loaded kernel drivers and modules, reporting their names, base addresses, and sizes. This directly supports building a baseline comparison for rootkit detection. The plugin works on Windows memory images and is the standard Volatility 3 replacement for the legacy Volatility 2 modlist plugin.

Why this answer

windows.modules enumerates loaded kernel modules by traversing PsLoadedModuleList, yielding names, base addresses, and sizes suitable for baseline comparison. The other plugins target different artifacts: driverscan finds driver objects via pool scanning, svcscan lists services, and psscan recovers process objects. Only windows.modules directly satisfies the stated requirement on a Windows memory image.

Exam trap

The trap here is confusing module listing with driver scanning, since both relate to kernel code but produce different evidence sets.

33
MCQeasy

A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?

A.windows.cmdline
B.windows.psscan
C.windows.pslist
D.windows.pstree
AnswerB

windows.psscan scans physical memory for process objects, including those that have been terminated but not yet overwritten. It can find residual process structures that are no longer in the active process list. This makes it the correct plugin to identify terminated processes that may still have forensic artifacts in memory.

Why this answer

The windows.psscan plugin scans physical memory for process objects, which allows it to find processes that have been terminated but whose structures have not been overwritten. This is useful for identifying residual evidence from terminated processes. In contrast, pslist and pstree only show active processes, and cmdline provides arguments for active processes.

Therefore, psscan is the correct choice for finding terminated processes in a memory dump.

Exam trap

The trap here is assuming that terminated processes are completely removed from memory, but their structures can linger until overwritten, which psscan can detect.

34
MCQmedium

Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?

A.pslist
B.malfind
C.handles
D.dlllist
AnswerB

The malfind plugin identifies memory regions that are both executable and private (not mapped to a file on disk). This is a strong indicator of injected code, as most legitimate executables are backed by files. It is the go-to tool for finding shellcode and non-persistent malicious code running in memory.

Why this answer

The 'malfind' plugin scans memory for regions that are marked as executable (X) but are not backed by a file on disk (VAD tags). This is the standard method for finding shellcode or injected DLLs, which are common in fileless malware. It matters because attackers often use memory injection to bypass signature-based antivirus, and detecting these unbacked regions is the primary way to uncover such hidden malicious execution.

Exam trap

Candidates often choose general process listing plugins like pslist, which do not inspect memory permissions or identify unbacked executable regions effectively.

35
MCQmedium

Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?

A.The thread environment block (TEB)
B.The process security token
C.The process environment block (PEB)
D.The registry hive file for the user
AnswerB

The process security token is a kernel object that represents the user's security context. It contains the SIDs for the user and their groups, which directly indicate the account identity that owns the process, providing the necessary evidence for identifying which user account executed the malware.

Why this answer

In Windows, every process is associated with a security token object that defines the user's identity, privileges, and groups. By extracting the security token structure associated with an EPROCESS object in memory, an analyst can determine the exact user context under which the process is executing. This is vital for determining if a process was launched with system privileges or by a compromised local user account during an incident.

Exam trap

Candidates often look for the user's profile path or environmental variables, which can be spoofed, rather than the kernel-level security token which serves as the authoritative source for process identity.

36
Multi-Selecthard

A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)

Select 2 answers
A.A process with a large number of handles to named pipes
B.A process whose working set is larger than its private commit size
C.A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk
D.A DLL loaded from a path within the user's AppData directory
E.A thread whose start address falls outside any known module range in the process
AnswersC, E

Executable and writable memory that has no file backing is a classic indicator of injected code, because legitimate executables and DLLs are normally mapped from disk with read-only or execute-only protections. The combination of writability, executability, and no on-disk source strongly suggests an attacker allocated memory and wrote shellcode or a payload into it.

Why this answer

Process injection typically manifests as executable memory that is not backed by a file on disk and as threads whose start addresses fall outside any mapped module. These two findings together provide strong evidence that an attacker wrote and executed code within another process, whereas handle counts, working set ratios, and AppData DLL loads have legitimate explanations and are not specific to injection.

Exam trap

The trap here is treating any unusual process characteristic, such as a DLL loaded from AppData or a high handle count, as proof of injection, when injection specifically requires executable code in an unbacked region or a thread executing outside known modules.

37
MCQmedium

You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?

A.IDT (Interrupt Descriptor Table)
B.GDT (Global Descriptor Table)
C.SSDT (System Service Descriptor Table)
D.PTE (Page Table Entry)
AnswerC

The SSDT contains an array of function pointers that define the kernel services available to user applications. Malware frequently overwrites these pointers to redirect execution flow to malicious code, allowing for the subversion of system APIs without triggering traditional file-based detection mechanisms during memory forensics analysis.

Why this answer

The System Service Descriptor Table (SSDT) maps system calls to kernel-mode functions. Rootkits often modify these pointers to intercept process execution. By comparing the SSDT addresses against the kernel's base image, analysts can identify unauthorized redirections.

This is crucial for detecting stealthy malware that hides its presence by manipulating the standard system call flow, ensuring the integrity of core operating system operations.

Exam trap

Candidates often confuse the SSDT with the IDT or standard process environment blocks, misidentifying which table specifically handles system service dispatching.

38
MCQhard

An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?

A.windows.driverirp
B.windows.devicetree
C.windows.ssdt
D.windows.callbacks
AnswerC

windows.ssdt parses the System Service Dispatch Table and compares each entry to the expected function based on the kernel module's export table, flagging entries that point outside the owning module. This directly detects SSDT hooks used by rootkits. It is the correct plugin for identifying hooked system service functions in this scenario.

Why this answer

The windows.ssdt plugin specifically parses the System Service Dispatch Table and compares each service routine pointer to the expected function address within the owning kernel module. Discrepancies indicate hooks, often used by rootkits to intercept system calls. The other plugins focus on callbacks, IRP handlers, or device trees, none of which directly analyze the SSDT for hooked entries.

Exam trap

The trap here is conflating different kernel hooking techniques, such as SSDT hooking versus IRP hooking or callback manipulation, and selecting a plugin that targets the wrong structure.

39
Multi-Selecthard

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

Select 2 answers
A.Processes present in windows.psscan but absent in windows.pslist are likely hidden by rootkit activity.
B.windows.psscan may report processes that have already terminated but whose EPROCESS structures have not been overwritten.
C.Processes present in windows.pslist but absent in windows.psscan indicate that the process terminated normally and its memory was freed.
D.If windows.psscan and windows.pslist produce identical output, it definitively proves that no rootkit is present on the system.
E.windows.pslist relies on pool tag scanning, while windows.psscan walks the active process list.
AnswersA, B

windows.psscan uses pool tag scanning to find EPROCESS structures regardless of whether they are linked in the active list. If a process appears in psscan but not pslist, it suggests the process was unlinked, a common rootkit technique. This discrepancy is a key indicator of hidden processes, making this statement correct.

Why this answer

The correct statements highlight that windows.psscan can reveal processes hidden from the active list and may also report terminated processes whose structures remain. These behaviors are essential for detecting rootkits that unlink processes. The other statements contain factual errors about the tools' methods or draw unsupported conclusions from identical output.

Exam trap

The trap here is assuming that any discrepancy between pslist and psscan automatically indicates malicious activity, when psscan can also report terminated processes or false positives due to memory reuse.

40
MCQhard

An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?

A.The unbacked regions are likely legitimate DLLs loaded from disk but with modified permissions due to process hardening.
B.The unbacked regions are indicative of injected code or shellcode, as they do not correspond to any file on disk and have suspicious permissions.
C.The unbacked regions are artifacts of the Volatility plugin itself, which may incorrectly report memory as unbacked due to parsing errors.
D.The unbacked regions are likely due to memory compression or paging, where the file backing was temporarily removed from the working set.
AnswerB

Unbacked memory regions with PAGE_EXECUTE_READWRITE and MZ headers are classic signs of code injection. Legitimate executables and DLLs are backed by files on disk. The absence of a file mapping indicates the code was placed directly into memory, often by process injection techniques. This is a key finding in fileless malware investigations and warrants further analysis of the injected content.

Why this answer

In memory forensics, unbacked memory regions with PAGE_EXECUTE_READWRITE protection and executable content such as an MZ header strongly suggest injected code or shellcode. Legitimate code is typically backed by a file on disk via a mapped section. The lack of file backing means the code was likely written directly into the process's address space by an injection technique, a common characteristic of fileless malware.

This finding should prompt further extraction and analysis of the injected payload.

Exam trap

The trap here is assuming that unbacked RWX regions are benign due to memory management quirks like paging, when they are actually a primary indicator of code injection in fileless attacks.

41
MCQhard

A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?

A.windows.pslist will show more processes than windows.psscan because it includes terminated processes that are still in memory.
B.windows.psscan will show more processes than windows.pslist because it can detect processes that have been unlinked from the active process list.
C.Both plugins will show the same number of processes because they both use the same underlying data structure.
D.windows.psscan will show fewer processes than windows.pslist because it relies on a linked list that the rootkit modifies.
AnswerB

windows.psscan scans physical memory for process objects using pool tag scanning, independent of the active process list. A rootkit that unlinks a process from the list will hide it from windows.pslist, but the process object may still reside in memory and be detected by windows.psscan. Therefore, windows.psscan is likely to show more processes, revealing the hidden one.

Why this answer

windows.pslist enumerates processes by following the active process list, which a rootkit can manipulate by unlinking its process. windows.psscan, however, scans memory for process objects using pool tags, which does not rely on the list. Therefore, in the presence of a process-unlinking rootkit, windows.psscan will detect the hidden process, resulting in a higher process count compared to windows.pslist. This discrepancy is a key indicator of hidden processes.

Exam trap

The trap here is assuming that both plugins rely on the same process list and would show identical results, missing that windows.psscan uses independent memory scanning to uncover unlinked processes.

42
MCQhard

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

A.The Master File Table (MFT)
B.The thread list in the scheduler
C.The user-mode Process Environment Block (PEB)
D.The System Service Descriptor Table (SSDT)
AnswerB

The Windows kernel scheduler relies on thread objects to allocate CPU time. Since the kernel must track every active thread to function, comparing the thread list against the EPROCESS list allows an analyst to find processes that have unlinked themselves from the active process list but are still running.

Why this answer

Cross-view analysis involves comparing the results of different enumeration methods to find inconsistencies. While the EPROCESS list (ActiveProcessLinks) is easily manipulated by rootkits to hide processes, the thread-based enumeration is much harder to hide, as the Windows scheduler must be aware of every thread to execute it. By iterating through all threads in the system, an analyst can identify processes that are excluded from the primary link list but are still actively executing.

Exam trap

Candidates often select the handle table or loaded module list, which are also easily manipulated by rootkits, failing to recognize that the scheduler's thread list is the most fundamental execution primitive.

43
Multi-Selecthard

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Select 2 answers
A.pslist enumeration
B.psscan pool tag analysis
C.Handle table analysis
D.Task Manager API polling
E.Registry hive parsing
AnswersB, C

The psscan plugin searches for EPROCESS objects by scanning memory for specific pool tags. This method does not rely on the integrity of the linked list pointers, making it highly effective at finding processes that have been unlinked or hidden by malicious kernel-mode activity during the investigation.

Why this answer

Detecting hidden processes requires comparing results from multiple analysis techniques. Traversing linked lists (pslist) is easily bypassed, so analysts use pool tag scanning (psscan) and cross-referencing with other structures like the Handle Table. These methods are critical because they bypass standard OS reporting mechanisms, ensuring that malware hiding via DKOM or other techniques is identified by looking at the raw physical memory contents directly.

Exam trap

Candidates frequently rely exclusively on standard pslist output during memory analysis, failing to utilize pool tag scanning and handle tables to catch hidden processes.

44
MCQmedium

During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?

A.The memory region is likely a legitimate dynamically allocated buffer used by explorer.exe for temporary data storage.
B.The memory region is likely a memory-mapped file that was paged out and later paged back in without file backing due to a system error.
C.The memory region is a false positive because windows.malfind often flags legitimate JIT-compiled code from .NET applications.
D.The memory region indicates that explorer.exe has been injected with malicious code, as it exhibits characteristics of process hollowing or reflective DLL injection.
AnswerD

PAGE_EXECUTE_READWRITE memory containing a PE header and not backed by a file is a classic indicator of code injection. Malware often uses techniques like reflective DLL injection or process hollowing to execute code within a legitimate process. The lack of file backing means the code was not loaded from disk, further supporting malicious injection.

Why this answer

A memory region with PAGE_EXECUTE_READWRITE protection, containing a PE header, and not backed by a file is a strong indicator of code injection. Legitimate processes rarely allocate such memory, and the presence of a PE header suggests a portable executable was loaded directly into memory. This is consistent with techniques like reflective DLL injection or process hollowing, where malicious code is executed within a trusted process to evade detection.

Exam trap

The trap here is dismissing the finding as a false positive due to legitimate JIT or memory-mapped files, ignoring that unbacked executable memory with a PE header is a hallmark of injection.

45
MCQmedium

When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?

A.The process is a system idle thread.
B.The process was likely orphaned by its parent.
C.The memory dump is corrupted.
D.The process is a legitimate background service.
AnswerB

Orphaned processes occur when the parent process has terminated. In forensic analysis, this is frequently seen with malware that uses a launcher process to execute a payload and then exits. It serves as a significant indicator of potential malicious activity, warranting a deeper look at the process's creation time.

Why this answer

A process with a non-existent parent ID often points to a 'orphaned' process, which is common when the parent process has already exited or was hidden. This is a red flag for malicious activity, as rootkits or malware often spawn sub-processes and then terminate the parent to hide the chain of execution. Identifying this is key to reconstructing the infection vector and timeline during a forensic investigation.

Exam trap

Candidates often assume a non-existent parent process ID indicates a system corruption error rather than investigating potential parent-child process spoofing or orphan processes.

46
MCQmedium

You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?

A.windows.modscan
B.windows.modules
C.windows.driverscan
D.windows.driverirp
AnswerA

windows.modscan scans kernel pool memory for module structures and can identify modules that were loaded and later unloaded, because their metadata may remain in pool even after removal from the active module list. This directly addresses the need to find previously loaded drivers that are no longer active, making it the correct plugin for this scenario.

Why this answer

To find drivers that were loaded and then unloaded, you need a plugin that scans kernel pool for module structures rather than relying on the active PsLoadedModuleList. windows.modscan performs exactly that pool scan and can recover residual module metadata, whereas the other plugins either list only active modules or focus on driver objects and IRP hooks, which would not reliably surface an unloaded driver.

Exam trap

The trap here is assuming that windows.modules will show all drivers that were ever loaded, when in fact it only shows currently loaded modules and misses unloaded ones.

47
MCQhard

Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?

A.It encrypts the entire memory dump
B.It hides the process by unlinking it from the process list
C.It prevents the acquisition of the memory dump
D.It modifies the CPU instructions directly
AnswerB

The Windows API follows a doubly-linked list of process objects to enumerate running programs. By removing the process node from this list, a rootkit makes the process invisible to any tool using the API, even though the process continues to run because the scheduler still tracks it.

Why this answer

Traditional tools rely on the Windows API to list processes and threads. These APIs query the kernel's process list (ActiveProcessLinks). DKOM allows a rootkit to unlink a process from this list while leaving the process structure intact so it can still be scheduled for execution.

Because the API only reports what the kernel's linked list reveals, the hidden process effectively disappears from standard tools, requiring forensic analysts to use memory-parsing techniques.

Exam trap

Students often think standard task manager tools or Windows APIs can expose DKOM rootkits, forgetting that these APIs rely entirely on kernel-managed linked lists.

48
MCQhard

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

A.The process is running a standard, signed driver
B.The process has been infected via code injection
C.The process is using a standard heap allocation
D.The memory segment is a legitimate shared DLL
AnswerB

The 'MZ' signature identifies a portable executable file. Finding this header inside a memory segment that lacks file-backing and is set to RWX permissions confirms that a complete binary payload was injected into the process memory, which is a hallmark of sophisticated process injection attacks.

Why this answer

The presence of the 'MZ' header (the magic bytes for a Windows PE executable) in a memory region that is not backed by a file on disk (VadS) and is marked as PAGE_EXECUTE_READWRITE is definitive proof of an injected executable. The malware has loaded a complete, valid PE file directly into memory to run its payload, which is a classic indicator of advanced fileless malware that bypasses file-system-based security controls.

Exam trap

Candidates often mistake the presence of an MZ header for a simple file mapping, failing to notice that the memory region is private (not file-backed) and has suspicious RWX permissions.

49
MCQmedium

You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?

A.windows.handles
B.windows.filescan
C.windows.privs
D.windows.dlllist
AnswerA

windows.handles lists the handles open in each process, including the object type, name, and access rights. For a file handle, it shows the full path and the granted access, which directly answers the question about the file's path and access type. This plugin is specifically designed to enumerate handles, making it the correct choice.

Why this answer

To find the full path and access type of a file handle, you need a plugin that enumerates handles per process. windows.handles provides exactly that, showing the object name (full path) and granted access for each handle. The other plugins focus on scanning file objects without process association, listing loaded DLLs, or displaying privileges, none of which directly answer the question about a specific handle.

Exam trap

The trap here is thinking that filescan will show which process has the file open, but filescan only lists file objects in memory without linking them to processes or showing access rights.

50
Multi-Selectmedium

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Select 2 answers
A.The bit-depth of the monitor attached to the server
B.The footprint of the acquisition tool in RAM
C.The likelihood of a kernel panic during acquisition
D.The total capacity of the hard drive
E.The current time zone of the server
AnswersB, C

Any tool executed on a system modifies memory. Minimizing the size and scope of the memory acquisition tool is vital to ensure that the evidence is not corrupted or overwritten. Forensic analysts prioritize tools that have a small footprint to maintain the integrity of the captured image.

Why this answer

When performing memory acquisition, minimizing the footprint on the target system is essential to prevent the overwriting of volatile artifacts. Furthermore, the selection of the acquisition tool must account for potential security software interference that could cause a system crash or trigger alerts. These factors ensure that the resulting image is a forensically sound representation of the system state at the time of capture, avoiding unnecessary collateral damage to the evidence.

Exam trap

Candidates often prioritize the speed of acquisition or the amount of data captured, ignoring the critical risk of system instability or kernel panics that can destroy volatile memory evidence.

51
MCQhard

During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?

A.windows.dlllist
B.windows.cmdline
C.windows.pstree
D.windows.pslist
AnswerC

windows.pstree displays processes in a hierarchical tree based on parent-child relationships, making it easy to spot anomalies like a svchost.exe with an unexpected parent. It shows the PPID and the actual parent process, helping verify legitimacy. This plugin is ideal for investigating process spoofing by visualizing the process tree.

Why this answer

The windows.pstree plugin is designed to display processes in a tree structure, showing parent-child relationships. This makes it easy to spot a svchost.exe with an unusual parent, such as a non-system process, which is a common sign of process spoofing. Other plugins like pslist, cmdline, and dlllist do not provide this hierarchical view, making pstree the correct choice for verifying process legitimacy.

Exam trap

The trap here is relying on a flat process list that shows PPIDs but not the actual parent process, which can be misleading if the PPID is spoofed.

52
Multi-Selectmedium

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

Select 3 answers
A.Thread Local Storage (TLS) pointers
B.Stack base and limit addresses
C.Exception handler chain head
D.Active process list pointer
E.Kernel-mode privilege level
AnswersA, B, C

The TEB contains the TLS array, which is used by threads to store and retrieve data that is unique to that specific thread. Malware often leverages TLS callbacks to execute code before the main entry point, making the inspection of this TEB structure vital for uncovering early-stage malicious execution.

Why this answer

The TEB is a user-mode structure that maintains thread-specific data, including the Thread Local Storage (TLS) array, exception handling chains, and the stack base/limit. Accessing the TEB is essential for forensic analysts because it helps decode how a specific thread executes, allows for the reconstruction of thread-local malware behavior, and provides insights into how the application manages its execution environment and exception handling.

Exam trap

Candidates often confuse the TEB with the PEB, mistakenly including process-wide information like environment variables or loader data, which are stored in the PEB rather than the thread-specific TEB structure.

53
MCQmedium

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

A.The memory segment is a standard heap allocation
B.The memory segment is a malicious injection
C.The memory segment is a legitimate shared library
D.The memory segment is part of the system kernel
AnswerB

The combination of Execute, Read, and Write permissions along with the lack of file-backing is a high-confidence indicator of injected code. This configuration allows a process to write a payload to memory and then immediately execute it, which is the standard methodology for process injection attacks.

Why this answer

The combination of PAGE_EXECUTE_READWRITE protection and the absence of an associated file (File: None) is a classic indicator of malicious code injection. Normal applications rarely allocate memory that is simultaneously writable and executable, as this violates standard security practices like Data Execution Prevention (DEP). The lack of a file-backing suggests the code resides entirely in memory, a common technique for fileless malware to avoid detection by traditional on-disk antivirus scanners.

Exam trap

Candidates often misinterpret PAGE_EXECUTE_READWRITE allocations as normal application behavior or routine caching, ignoring the strong malicious indicator of unbacked executable memory.

Ready to test yourself?

Try a timed practice session using only Introduction to Memory Forensics questions.