GCFA Introduction to Memory Forensics Practice Question
Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?
⚠ Common exam trap
Students often think standard task manager tools or Windows APIs can expose DKOM rootkits, forgetting that these APIs rely entirely on kernel-managed linked lists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It hides the process by unlinking it from the process list
Traditional tools rely on the Windows API to list processes and threads. These APIs query the kernel's process list (ActiveProcessLinks). DKOM allows a rootkit to unlink a process from this list while leaving the process structure intact so it can still be scheduled for execution. Because the API only reports what the kernel's linked list reveals, the hidden process effectively disappears from standard tools, requiring forensic analysts to use memory-parsing techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It encrypts the entire memory dump
Why it's wrong here
DKOM does not encrypt memory. It modifies the internal kernel pointers that the operating system uses to track objects. Encryption is a separate issue related to data at rest or in transit, and it does not explain why the process becomes invisible to the standard Windows API.
- ✓
It hides the process by unlinking it from the process list
Why this is correct
The Windows API follows a doubly-linked list of process objects to enumerate running programs. By removing the process node from this list, a rootkit makes the process invisible to any tool using the API, even though the process continues to run because the scheduler still tracks it.
- ✗
It prevents the acquisition of the memory dump
Why it's wrong here
DKOM is a technique for hiding objects within the memory that has already been acquired. It does not interfere with the ability of a forensic tool to dump the physical RAM. The challenge is in the analysis phase, not the acquisition phase, as the data is captured correctly.
- ✗
It modifies the CPU instructions directly
Why it's wrong here
DKOM specifically targets kernel objects, not the raw CPU instruction set. Modifying instructions is a different technique, such as binary patching or hooking. DKOM is strictly focused on altering the kernel's metadata structures to deceive the operating system's management functions and security monitoring tools.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.