Courseiva

GCFA Introduction to Memory Forensics Practice Question

During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?

⚠ Common exam trap

The trap here is assuming that windows.pstree, which shows parent-child relationships, would automatically reveal hidden processes, but it only displays processes already present in the active list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.psscan

windows.psscan uses pool tag scanning to locate EPROCESS structures in memory, which can uncover processes that have been unlinked from the active process list by rootkits or other hiding techniques. By comparing its output with windows.pslist, an analyst can identify discrepancies indicating hidden processes. The other plugins either rely on the active list or serve different purposes, such as command-line retrieval or network connection enumeration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.psscan

    Why this is correct

    windows.psscan scans physical memory for EPROCESS structures using pool tag scanning, which can reveal processes that are not linked in the active process list due to rootkit unlinking or other hiding techniques. This directly addresses the need to find hidden processes by comparing against windows.pslist. It is the correct plugin for detecting discrepancies that indicate process hiding.

  • ✗

    windows.netscan

    Why it's wrong here

    windows.netscan enumerates network connections and listening sockets by scanning for network-related structures. It does not enumerate processes or detect hidden processes. While it can reveal suspicious network activity, it does not address the specific need to find processes hidden from the active process list. Thus, it is not the correct plugin here.

  • ✗

    windows.pstree

    Why it's wrong here

    windows.pstree displays processes in a tree structure based on parent-child relationships from the active process list. It relies on the same linked list as windows.pslist and does not perform pool tag scanning, so it cannot reveal unlinked or hidden processes. While useful for visualizing process hierarchy, it does not help identify processes hidden from the active list.

  • ✗

    windows.cmdline

    Why it's wrong here

    windows.cmdline retrieves command-line arguments for processes by reading the process environment block (PEB). It does not scan for hidden processes or compare different process enumeration methods. Its purpose is to provide context about how processes were launched, not to detect processes missing from the active list. Therefore, it is not suitable for this task.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.