GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?
⚠ Common exam trap
Candidates often suggest checking netstat output or active connection logs, which can be hooked or hidden by rootkits, rather than inspecting the kernel-level TCP structures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP Endpoint structures
The TCP Endpoint structures in kernel memory are essential for mapping network activity to process ownership. Attackers often attempt to hide connections using rootkit techniques, but these structures in memory usually remain accurate. Linking a specific PID to a remote IP address allows the analyst to identify Command and Control (C2) communication, which is the most reliable way to identify an active, compromised host during a live incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS cache
Why it's wrong here
The DNS cache contains recently resolved hostnames, which is useful for identifying the domains an attacker might be communicating with, but it does not link those connections to specific PIDs or show real-time, active socket states. It is a historical record of lookups, not a snapshot of current connections.
- ✓
TCP Endpoint structures
Why this is correct
TCP Endpoint structures in memory store the state of all active and listening network connections, including the associated process ID. By parsing these structures from a memory dump, an analyst can definitively link network traffic to a specific, potentially malicious process, regardless of whether the connection is hidden from standard OS tools.
- ✗
Shimcache
Why it's wrong here
Shimcache is a disk-based registry artifact that lists execution history. It does not record network activity or link processes to active sockets. It is entirely unsuitable for identifying network-based communication or mapping connections to specific PIDs in a volatile memory environment during an incident.
- ✗
Amcache.hve
Why it's wrong here
Amcache.hve is a registry hive that stores metadata about files, including their SHA1 hash and the last time they were run. It has no visibility into the network stack or process communication. It is a file-centric artifact and cannot reveal information about active network connections or socket states.
Visual reference
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.