GCFA Introduction to Memory Forensics Practice Question
Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?
⚠ Common exam trap
Candidates frequently rely exclusively on standard pslist output during memory analysis, failing to utilize pool tag scanning and handle tables to catch hidden processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
psscan pool tag analysis
Detecting hidden processes requires comparing results from multiple analysis techniques. Traversing linked lists (pslist) is easily bypassed, so analysts use pool tag scanning (psscan) and cross-referencing with other structures like the Handle Table. These methods are critical because they bypass standard OS reporting mechanisms, ensuring that malware hiding via DKOM or other techniques is identified by looking at the raw physical memory contents directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pslist enumeration
Why it's wrong here
The pslist command follows the ActiveProcessLinks list in the kernel. This is a common API-reliant method that malware can easily evade by unlinking the process structure. It is considered an unreliable method for finding hidden processes, as it only shows what the kernel currently acknowledges as active.
- ✓
psscan pool tag analysis
Why this is correct
The psscan plugin searches for EPROCESS objects by scanning memory for specific pool tags. This method does not rely on the integrity of the linked list pointers, making it highly effective at finding processes that have been unlinked or hidden by malicious kernel-mode activity during the investigation.
- ✓
Handle table analysis
Why this is correct
Analyzing handle tables allows an investigator to identify process objects that are referenced even if they do not appear in the primary ActiveProcessLinks list. This provides a secondary source of truth, making it a reliable way to uncover processes attempting to evade detection via standard kernel list manipulation.
- ✗
Task Manager API polling
Why it's wrong here
Task Manager relies on the same internal Windows APIs as pslist. If a process is hidden from the kernel's active process list, Task Manager will not display it. Relying on live system APIs during a forensic investigation is dangerous and often leads to missing malicious processes hidden by rootkits.
- ✗
Registry hive parsing
Why it's wrong here
Registry parsing can reveal persistence mechanisms but does not identify running processes in memory. While useful for finding what should be running, it does not confirm the actual presence of a malicious process in memory at the time of capture, nor does it detect hidden, non-persistent, memory-resident malware.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.