Courseiva

GCFA Introduction to Memory Forensics Practice Question

During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?

⚠ Common exam trap

The trap here is assuming that winlogon.exe or lsass.exe directly store the interactive user's SID in their process structures, when the reliable source is the token of a user-context process like explorer.exe.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token object referenced by explorer.exe, because its user SID identifies the interactively logged-on account.

The interactive user's identity is tied to the token of a process running in that user's session, such as explorer.exe. Extracting the token SID from explorer.exe's EPROCESS in the memory image confirms which account was interactively logged on. Other structures like KDBG or winlogon's EPROCESS do not directly hold the interactive user SID, making them unsuitable for this specific attribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The KDBG structure, because it stores the list of logged-on user sessions and their SIDs.

    Why it's wrong here

    The KDBG (Kernel Debugger Block) contains kernel debugging information such as the PsActiveProcessHead list and module list, but it does not store user session SIDs. Confusing KDBG with session-related structures is a common error; KDBG is useful for locating process lists, not for identifying interactive users.

  • ✗

    The EPROCESS block for winlogon.exe, because it stores the Security Identifier (SID) of the interactive user.

    Why it's wrong here

    The EPROCESS block of winlogon.exe represents the SYSTEM-owned logon process and does not hold the interactive user's SID. While winlogon manages session creation, the user identity is linked through the logon session structures, not directly in winlogon's EPROCESS. Relying on this structure would lead to misidentifying the interactive user in most scenarios.

  • ✓

    The token object referenced by explorer.exe, because its user SID identifies the interactively logged-on account.

    Why this is correct

    Explorer.exe runs in the interactive user's context, and its primary token contains the user SID of that account. Parsing the token from explorer.exe's EPROCESS in memory reveals the interactive user. This is a standard technique in memory forensics for attributing activity to a specific logged-on user when no other session artifacts are available.

  • ✗

    The PEB of lsass.exe, because it caches the credentials of the interactive user in plaintext.

    Why it's wrong here

    Lsass.exe hosts authentication packages and may hold credential material, but its PEB does not store the interactive user's SID in plaintext. The PEB contains image loader and process parameters, not session identity. Seeking the interactive user's SID in lsass's PEB would not reliably identify the logged-on account.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.