Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?

⚠ Common exam trap

Candidates often suggest checking netstat output or active connection logs, which can be hooked or hidden by rootkits, rather than inspecting the kernel-level TCP structures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP Endpoint structures

The TCP Endpoint structures in kernel memory are essential for mapping network activity to process ownership. Attackers often attempt to hide connections using rootkit techniques, but these structures in memory usually remain accurate. Linking a specific PID to a remote IP address allows the analyst to identify Command and Control (C2) communication, which is the most reliable way to identify an active, compromised host during a live incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS cache

    Why it's wrong here

    The DNS cache contains recently resolved hostnames, which is useful for identifying the domains an attacker might be communicating with, but it does not link those connections to specific PIDs or show real-time, active socket states. It is a historical record of lookups, not a snapshot of current connections.

  • ✓

    TCP Endpoint structures

    Why this is correct

    TCP Endpoint structures in memory store the state of all active and listening network connections, including the associated process ID. By parsing these structures from a memory dump, an analyst can definitively link network traffic to a specific, potentially malicious process, regardless of whether the connection is hidden from standard OS tools.

  • ✗

    Shimcache

    Why it's wrong here

    Shimcache is a disk-based registry artifact that lists execution history. It does not record network activity or link processes to active sockets. It is entirely unsuitable for identifying network-based communication or mapping connections to specific PIDs in a volatile memory environment during an incident.

  • ✗

    Amcache.hve

    Why it's wrong here

    Amcache.hve is a registry hive that stores metadata about files, including their SHA1 hash and the last time they were run. It has no visibility into the network stack or process communication. It is a file-centric artifact and cannot reveal information about active network connections or socket states.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.