Courseiva

GCFA · topic practice

Introduction to Memory Forensics practice questions

This domain covers acquiring and interpreting Windows memory images with Volatility 3, focusing on detecting fileless malware, hidden or unlinked processes, and network artifacts from terminated processes. Questions present realistic incident scenarios and require selecting the correct plugin, interpreting its output, and drawing defensible forensic conclusions from memory-resident evidence.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Introduction to Memory Forensics

What the exam tests

What to know about Introduction to Memory Forensics

A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.

Running windows.malfind to locate injected or suspicious executable memory regions in a process

Using windows.psscan to find processes unlinked from the active process list

Correlating windows.netscan connections with processes absent from windows.pslist

Understanding WinPmem acquisition and what a full physical memory image contains

Watch out for

Common Introduction to Memory Forensics exam traps

  • ▸Assuming windows.pslist shows all processes; rootkits can unlink processes, so windows.psscan is needed to reveal hidden ones
  • ▸Treating any malfind hit as confirmed malware; legitimate injected or packed code can also appear, so corroborate with other artifacts
  • ▸Concluding a network connection is inactive because its process is missing from pslist, when the process may simply be terminated or hidden

Practice set

Introduction to Memory Forensics questions

20 questions · select your answer, then reveal the explanation

What is the primary forensic benefit of utilizing an offline memory image rather than a live response capture for a deep-dive investigation?

When examining memory, which TWO of the following are valid techniques for detecting malicious network activity that might not be visible in standard OS logs?

You encounter a suspicious process with an 'ExitTime' value set. What is the forensic implication of this finding?

During a memory forensics investigation of a Windows 10 system, an analyst runs the Volatility 3 windows.malfind plugin and observes a process with memory regions that are PAGE_EXECUTE_READWRITE and contain MZ headers. The analyst wants to extract the injected executable from these memory regions for further analysis. Which Volatility 3 plugin should the analyst use to dump these suspicious memory regions to disk?

During memory forensics of a Windows 10 system, you observe a process named 'svchost.exe' with a parent process ID (PPID) that does not match any known service host parent. You suspect process hollowing. Which Volatility 3 plugin would best help you identify the discrepancy between the process's apparent image path and its actual memory-resident executable?

An incident responder captures a memory image from a Windows 10 workstation using WinPmem. During analysis with Volatility 3, the examiner runs the windows.pstree plugin and notices a process named svchost.exe with a PID of 3216 that has no parent process (PPID points to a non-existent PID). The examiner suspects process hiding. Which of the following is the most likely explanation for this observation?

An analyst is examining a memory image from a Windows 10 system infected with malware. The analyst runs the Volatility 3 plugin windows.malfind and observes several memory regions with PAGE_EXECUTE_READWRITE permissions and no mapped file. To further investigate these regions, which Volatility 3 plugin should the analyst use to extract the injected code for analysis?

An incident responder captures a raw memory image from a Windows 10 workstation using WinPmem while the machine is running. The image is later loaded into Volatility 3 on a Linux analysis host. The analyst needs to enumerate active network connections that were present at the time of capture. Which Volatility 3 plugin should the analyst run first to satisfy this requirement?

During a malware investigation, an analyst loads a Windows memory image into Volatility 3 and observes that a process named svchost.exe has a parent process ID (PPID) pointing to explorer.exe, and its image path is C:\Users\Public\svchost.exe. The analyst wants to determine whether the process is a masquerading executable rather than the legitimate service host. Which artifact should the analyst examine to compare the on-disk image path recorded in the process structure with the actual executable on disk?

An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

Exhibit

Exhibit A: Volatility pstree output
Name: svchost.exe | PID: 1240 | PPID: 988
Name: svchost.exe | PID: 1420 | PPID: 1240
Name: explorer.exe | PID: 1600 | PPID: 1240

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?

When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

Exhibit

Exhibit B: Volatility vadinfo output
Virtual Address: 0x00400000
Protection: PAGE_EXECUTE_READWRITE
File: None
Tag: VadS

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?

Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Introduction to Memory Forensics sessions

Start a Introduction to Memory Forensics only practice session

Every question in these sessions is drawn from the Introduction to Memory Forensics domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Introduction to Memory Forensics?
A candidate must acquire and analyze Windows memory with Volatility 3, choosing the right plugin for each artifact. The single most important thing is knowing that pslist can miss hidden processes, so psscan and malfind are essential for detecting unlinked or injected code.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Introduction to Memory Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the Introduction to Memory Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.