GCFA Introduction to Memory Forensics Practice Question
During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?
⚠ Common exam trap
The trap here is assuming any mismatch between network connections and the process list indicates active hiding, when stale structures from exited processes are a common benign cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The connections are likely residual artifacts from a terminated process, and the examiner should correlate timestamps and process IDs to confirm.
windows.netscan can surface network structures that outlive their owning process, so missing process entries alongside established connections often reflect terminated processes rather than hidden malware. Correlating process IDs, timestamps, and other artifacts is the proper next step. Claiming rootkit activity, image corruption, or a confirmed attack from this observation alone is premature and unsupported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The connections are proof of a network-based attack and should be reported as a confirmed incident.
Why it's wrong here
Established TCP connections alone do not prove an attack; they are common in normal operations. Without corroborating evidence such as malicious code, unusual destinations, or process ancestry, reporting a confirmed incident is unjustified. The examiner should gather additional context before escalating, as premature reporting can misdirect response efforts.
- ✗
The connections indicate that the memory image is corrupted and should be reacquired.
Why it's wrong here
Residual network connections do not indicate image corruption. Memory images routinely contain stale structures from exited processes. Reacquisition would not resolve the observation and would waste time. The correct response is to interpret the artifact in context, using timestamps and process correlation, rather than assuming the acquisition was faulty.
- ✗
The connections prove that a rootkit is hiding a running process from the process list.
Why it's wrong here
While rootkits can hide processes, residual network structures from terminated processes are a more common explanation. Concluding rootkit activity solely from missing process entries is premature. Proper analysis requires cross-checking with other plugins and artifacts to distinguish between a terminated process and an actively hidden one before making such a serious determination.
- ✓
The connections are likely residual artifacts from a terminated process, and the examiner should correlate timestamps and process IDs to confirm.
Why this is correct
windows.netscan parses network structures that may persist after a process exits, especially if the process object has not been fully reclaimed. Residual connections from terminated processes are common and should be validated by correlating process IDs, timestamps, and related artifacts rather than immediately concluding malicious activity. This cautious correlation approach avoids false positives.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.