Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?

⚠ Common exam trap

The trap here is trusting user-mode API outputs like Services.msc or sc query, which can be manipulated by a rootkit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyzing the memory image for service records using a tool like Volatility.

Rootkits often hook user-mode APIs to hide their presence, so tools that rely on those APIs (like Services.msc or sc query) may not show the malicious service. Memory forensics tools like Volatility directly parse kernel structures such as the service list, which are harder for rootkits to manipulate without causing instability. This allows detection of services that are hidden from standard interfaces. Antivirus may also be bypassed, making memory analysis the most effective approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analyzing the memory image for service records using a tool like Volatility.

    Why this is correct

    Memory forensics tools like Volatility can parse kernel data structures to enumerate services directly from memory, bypassing any API hooks or registry modifications. By examining the service list in memory, you can detect services that are hidden from user-mode APIs. This is the most effective method for identifying rootkit-hidden services, as it relies on the actual state of the system rather than potentially compromised interfaces.

  • ✗

    Running a full antivirus scan with updated signatures.

    Why it's wrong here

    Antivirus software may not detect a sophisticated rootkit, especially if it is custom or uses new techniques. The rootkit can also interfere with the antivirus's ability to scan. While antivirus is useful, it is not the most effective for detecting hidden services. Memory forensics is more reliable because it examines the system at a lower level.

  • ✗

    Enumerating services using the Services.msc GUI.

    Why it's wrong here

    The Services.msc GUI relies on the Windows Service Control Manager API, which can be hooked by a rootkit to hide malicious services. If the rootkit is active, the service will not appear in the list. Therefore, this method is unreliable for detecting hidden services. Memory forensics is needed to bypass the rootkit's deception.

  • ✗

    Comparing the output of 'sc query' with the service list from the registry.

    Why it's wrong here

    The 'sc query' command also uses the Service Control Manager API and can be subverted by a rootkit. While comparing with the registry might reveal discrepancies, the registry itself can be manipulated by a kernel-mode rootkit. This method is better than GUI alone but still not as robust as memory analysis, which directly examines kernel data structures.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.