Courseiva

GCFA Introduction to Memory Forensics Practice Question

During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?

⚠ Common exam trap

The trap here is relying on a flat process list that shows PPIDs but not the actual parent process, which can be misleading if the PPID is spoofed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.pstree

The windows.pstree plugin is designed to display processes in a tree structure, showing parent-child relationships. This makes it easy to spot a svchost.exe with an unusual parent, such as a non-system process, which is a common sign of process spoofing. Other plugins like pslist, cmdline, and dlllist do not provide this hierarchical view, making pstree the correct choice for verifying process legitimacy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    windows.dlllist

    Why it's wrong here

    windows.dlllist lists loaded DLLs for processes, which can reveal injected libraries but does not provide information about process parentage. It does not help in examining PPID or parent-child relationships. Hence, it is not suitable for investigating process spoofing in this context.

  • ✗

    windows.cmdline

    Why it's wrong here

    windows.cmdline shows command-line arguments for processes, which can be useful for detecting suspicious arguments but does not display parent-child relationships. It does not help in verifying the legitimacy of a parent process based on PPID. Therefore, it is not the right plugin for this task.

  • ✓

    windows.pstree

    Why this is correct

    windows.pstree displays processes in a hierarchical tree based on parent-child relationships, making it easy to spot anomalies like a svchost.exe with an unexpected parent. It shows the PPID and the actual parent process, helping verify legitimacy. This plugin is ideal for investigating process spoofing by visualizing the process tree.

  • ✗

    windows.pslist

    Why it's wrong here

    windows.pslist lists processes in a flat format with PPIDs but does not show the hierarchical relationship. While it provides PPID information, it does not visually map parent-child connections, making it harder to quickly identify anomalies. Thus, it is less effective for verifying process parentage in this scenario.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.