Courseiva

GCFA Introduction to Memory Forensics Practice Question

Exhibit

Exhibit A: Volatility pstree output
Name: svchost.exe | PID: 1240 | PPID: 988
Name: svchost.exe | PID: 1420 | PPID: 1240
Name: explorer.exe | PID: 1600 | PPID: 1240

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

⚠ Common exam trap

Candidates often misidentify legitimate svchost.exe behavior by assuming any child process of svchost.exe is malicious, failing to recognize that specific services like taskhostw.exe are legitimate children of svchost.exe.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The parent-child relationship of svchost.exe and explorer.exe

The exhibit shows explorer.exe being spawned by svchost.exe. In a standard Windows environment, explorer.exe is spawned by userinit.exe, which in turn is spawned by winlogon.exe. A service host process (svchost.exe) spawning the Windows shell is highly anomalous behavior. This pattern suggests an injection or a process replacement attack where a malicious service has hijacked the shell or launched a secondary GUI interface for persistent command and control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PID 1240 is assigned to svchost.exe

    Why it's wrong here

    Svchost.exe is a standard Windows service host process that typically runs multiple instances. Having multiple instances under different PIDs is expected behavior. The PID value itself is dynamic and does not inherently suggest malicious intent without context regarding its parent or child processes.

  • ✗

    The existence of two svchost.exe processes

    Why it's wrong here

    Windows architecture is designed to host multiple services within separate svchost.exe instances to increase stability and security. Seeing multiple instances of this process is standard behavior and does not represent an indicator of compromise unless the specific services hosted are unidentified or malicious.

  • ✓

    The parent-child relationship of svchost.exe and explorer.exe

    Why this is correct

    Explorer.exe is typically launched by userinit.exe during the login sequence. When svchost.exe, a process intended for background system services, spawns the shell, it indicates that the system has been compromised. This violation of established process lineage is a primary indicator of process injection or hollowing.

  • ✗

    The PID of explorer.exe is higher than svchost.exe

    Why it's wrong here

    Process IDs are assigned by the operating system kernel using a counter. Higher PIDs generally indicate processes that were started later than those with lower PIDs. Since explorer.exe typically starts after system services during the boot sequence, this behavior is perfectly normal and expected for Windows.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.