Courseiva

GCFA Introduction to Memory Forensics Practice Question

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

⚠ Common exam trap

Candidates often look for the command line in the EPROCESS structure itself, not realizing that the kernel does not store the full command-line string there, but rather points to the PEB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Process Environment Block (PEB)

Reconstructing command-line arguments is essential for understanding the specific intent of a malicious executable. The Process Environment Block (PEB) contains the command line string passed to a process at the time of its creation. By extracting this structure from memory, an analyst can reveal hidden parameters, remote IP addresses, or command flags that the malware author attempted to hide from the visual process list, providing critical context for the investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Master File Table (MFT)

    Why it's wrong here

    The MFT is a disk-based structure used to manage file system metadata. It does not contain information about the current execution state or command-line parameters of running processes. While it can show the file's existence, it cannot explain how that file was executed during the current session.

  • ✓

    The Process Environment Block (PEB)

    Why this is correct

    The PEB is a user-mode data structure that contains essential information about a process, including the full command line used to launch it. Accessing this via memory forensics allows analysts to recover the exact execution path and any arguments passed to the malicious process, which are often missing.

  • ✗

    The Registry Hive files

    Why it's wrong here

    Registry hives represent persistent configuration data stored on disk. While they may contain historical information about run keys or installed software, they do not track the dynamic command-line arguments passed to an active, running process in volatile memory during the current session of the operating system.

  • ✗

    The System Service Descriptor Table (SSDT)

    Why it's wrong here

    The SSDT is a kernel-mode table used to map system calls to their corresponding functions in memory. It is primarily used for intercepting kernel activity and does not store the user-level command-line strings that were used to launch a specific application process in the system's memory.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.