GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?
⚠ Common exam trap
The trap here is assuming that a missing parent process automatically indicates a hidden process or rootkit, when it is often just a terminated parent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The parent process has terminated, and the PPID is now stale.
When a parent process terminates, its child processes continue to run, and the child's PPID remains set to the now-invalid parent PID. This results in a stale PPID. The absence of PID 1234 in the active process list indicates that the parent has likely terminated, which is a normal occurrence and not inherently malicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The parent process has terminated, and the PPID is now stale.
Why this is correct
In Windows, when a parent process terminates, its child processes are not terminated. The PPID of a child remains pointing to the now-defunct parent PID. Since PID 1234 is not in the active process list, it likely terminated, leaving a stale PPID. This is a common forensic artifact and does not necessarily indicate malicious activity.
- ✗
The memory dump is corrupted and the process list is incomplete.
Why it's wrong here
A missing parent process in pslist does not imply memory corruption. It is normal for parents to terminate before children. The pslist plugin only shows active processes; a terminated parent will not appear. There is no evidence of corruption based solely on this observation.
- ✗
The process 'svchost.exe' is a known Windows service and its parent should always be 'services.exe'.
Why it's wrong here
While legitimate svchost.exe processes typically have services.exe as their parent, the absence of the parent in pslist does not prove that the parent was not services.exe. The parent could have been services.exe but terminated. Moreover, malware can name itself svchost.exe, so assuming legitimacy based on name is incorrect.
- ✗
The PPID indicates that the parent process is hidden by a rootkit and should be recovered using psscan.
Why it's wrong here
A missing parent in pslist could indicate a hidden process, but it is more commonly due to termination. While psscan might recover hidden processes, concluding a rootkit solely from a missing PPID is premature. Further analysis is needed to differentiate between a terminated process and a hidden one.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.