GCFA Introduction to Memory Forensics Practice Question
During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?
⚠ Common exam trap
The trap here is relying on a flat process list that shows PPIDs but not the actual parent process, which can be misleading if the PPID is spoofed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.pstree
The windows.pstree plugin is designed to display processes in a tree structure, showing parent-child relationships. This makes it easy to spot a svchost.exe with an unusual parent, such as a non-system process, which is a common sign of process spoofing. Other plugins like pslist, cmdline, and dlllist do not provide this hierarchical view, making pstree the correct choice for verifying process legitimacy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.dlllist
Why it's wrong here
windows.dlllist lists loaded DLLs for processes, which can reveal injected libraries but does not provide information about process parentage. It does not help in examining PPID or parent-child relationships. Hence, it is not suitable for investigating process spoofing in this context.
- ✗
windows.cmdline
Why it's wrong here
windows.cmdline shows command-line arguments for processes, which can be useful for detecting suspicious arguments but does not display parent-child relationships. It does not help in verifying the legitimacy of a parent process based on PPID. Therefore, it is not the right plugin for this task.
- ✓
windows.pstree
Why this is correct
windows.pstree displays processes in a hierarchical tree based on parent-child relationships, making it easy to spot anomalies like a svchost.exe with an unexpected parent. It shows the PPID and the actual parent process, helping verify legitimacy. This plugin is ideal for investigating process spoofing by visualizing the process tree.
- ✗
windows.pslist
Why it's wrong here
windows.pslist lists processes in a flat format with PPIDs but does not show the hierarchical relationship. While it provides PPID information, it does not visually map parent-child connections, making it harder to quickly identify anomalies. Thus, it is less effective for verifying process parentage in this scenario.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.