Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?

⚠ Common exam trap

Candidates often select generic process listing plugins like 'pslist' which only show process names, forgetting that specific argument flags require dedicated command-line extraction plugins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cmdline

The 'cmdline' plugin in Volatility 2 or the equivalent 'windows.cmdline' in Volatility 3 is essential for surfacing the exact arguments used to launch a process. Attackers frequently use command-line arguments to pass encoded payloads, configure malicious scripts, or perform lateral movement tasks. Identifying these arguments provides the context necessary to understand the intent of the process, which is often hidden when looking only at the process name or binary path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pstree

    Why it's wrong here

    Pstree is for viewing the process hierarchy, not for inspecting the internal details of a process's launch. While the hierarchy is important, it does not display the command-line arguments that are often the key to understanding the specific malicious action being performed by the process.

  • ✓

    cmdline

    Why this is correct

    The cmdline plugin specifically retrieves the command-line arguments from the process's PEB (Process Environment Block). This provides the full string used to start the process, which often includes malicious paths, obfuscated arguments, or external command-and-control parameters that are vital for forensic analysis of the execution.

  • ✗

    netscan

    Why it's wrong here

    Netscan is used to identify active or closed network connections in memory. While it is vital for identifying C2 traffic, it does not reveal the command-line parameters that were used to launch the processes responsible for those network connections. It is a complementary tool, not a replacement for cmdline.

  • ✗

    dlllist

    Why it's wrong here

    Dlllist displays the loaded DLLs for a process. While this is helpful for identifying malicious library injections, it does not expose the command-line arguments used at the start of the process. Relying on dlllist alone would leave the investigator without the context provided by the launch parameters.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.