GCFA Introduction to Memory Forensics Practice Question
When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?
⚠ Common exam trap
Candidates often select the handle table or loaded module list, which are also easily manipulated by rootkits, failing to recognize that the scheduler's thread list is the most fundamental execution primitive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The thread list in the scheduler
Cross-view analysis involves comparing the results of different enumeration methods to find inconsistencies. While the EPROCESS list (ActiveProcessLinks) is easily manipulated by rootkits to hide processes, the thread-based enumeration is much harder to hide, as the Windows scheduler must be aware of every thread to execute it. By iterating through all threads in the system, an analyst can identify processes that are excluded from the primary link list but are still actively executing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Master File Table (MFT)
Why it's wrong here
The MFT contains file metadata and has no inherent relationship to the Windows scheduler's process list. It cannot be used to detect hidden processes because it does not maintain a record of which applications are currently active or scheduled for execution by the Windows kernel.
- ✓
The thread list in the scheduler
Why this is correct
The Windows kernel scheduler relies on thread objects to allocate CPU time. Since the kernel must track every active thread to function, comparing the thread list against the EPROCESS list allows an analyst to find processes that have unlinked themselves from the active process list but are still running.
- ✗
The user-mode Process Environment Block (PEB)
Why it's wrong here
The PEB is managed by the user-mode process and can be easily modified or unlinked by malicious software. Relying on the PEB to verify a process list is ineffective because the rootkit can update the PEB to match the fake process list, maintaining the deception.
- ✗
The System Service Descriptor Table (SSDT)
Why it's wrong here
The SSDT handles system calls for kernel functions. While it can be hooked to redirect execution, it does not contain a list of all processes that are currently running. Using the SSDT to verify process existence is technically incorrect and would not reliably surface hidden process objects.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.