GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?
⚠ Common exam trap
Candidates often select generic process listing plugins like 'pslist' which only show process names, forgetting that specific argument flags require dedicated command-line extraction plugins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cmdline
The 'cmdline' plugin in Volatility 2 or the equivalent 'windows.cmdline' in Volatility 3 is essential for surfacing the exact arguments used to launch a process. Attackers frequently use command-line arguments to pass encoded payloads, configure malicious scripts, or perform lateral movement tasks. Identifying these arguments provides the context necessary to understand the intent of the process, which is often hidden when looking only at the process name or binary path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pstree
Why it's wrong here
Pstree is for viewing the process hierarchy, not for inspecting the internal details of a process's launch. While the hierarchy is important, it does not display the command-line arguments that are often the key to understanding the specific malicious action being performed by the process.
- ✓
cmdline
Why this is correct
The cmdline plugin specifically retrieves the command-line arguments from the process's PEB (Process Environment Block). This provides the full string used to start the process, which often includes malicious paths, obfuscated arguments, or external command-and-control parameters that are vital for forensic analysis of the execution.
- ✗
netscan
Why it's wrong here
Netscan is used to identify active or closed network connections in memory. While it is vital for identifying C2 traffic, it does not reveal the command-line parameters that were used to launch the processes responsible for those network connections. It is a complementary tool, not a replacement for cmdline.
- ✗
dlllist
Why it's wrong here
Dlllist displays the loaded DLLs for a process. While this is helpful for identifying malicious library injections, it does not expose the command-line arguments used at the start of the process. Relying on dlllist alone would leave the investigator without the context provided by the launch parameters.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.