GCFA Introduction to Memory Forensics Practice Question
You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?
⚠ Common exam trap
Candidates often confuse the SSDT with the IDT or standard process environment blocks, misidentifying which table specifically handles system service dispatching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSDT (System Service Descriptor Table)
The System Service Descriptor Table (SSDT) maps system calls to kernel-mode functions. Rootkits often modify these pointers to intercept process execution. By comparing the SSDT addresses against the kernel's base image, analysts can identify unauthorized redirections. This is crucial for detecting stealthy malware that hides its presence by manipulating the standard system call flow, ensuring the integrity of core operating system operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IDT (Interrupt Descriptor Table)
Why it's wrong here
The IDT handles interrupts and exceptions, not the direct mapping of system service requests. While rootkits may hook IDT entries to intercept hardware signals, the SSDT is the specific structure responsible for dispatching system calls from user mode into the kernel, making it the primary target for system-level hooking.
- ✗
GDT (Global Descriptor Table)
Why it's wrong here
The GDT defines the characteristics of segments used in protected mode, including memory limits and access rights. Modifying the GDT is common for privilege escalation, but it is not the mechanism used to redirect system calls, which is the specific function of the SSDT for kernel-mode operations.
- ✓
SSDT (System Service Descriptor Table)
Why this is correct
The SSDT contains an array of function pointers that define the kernel services available to user applications. Malware frequently overwrites these pointers to redirect execution flow to malicious code, allowing for the subversion of system APIs without triggering traditional file-based detection mechanisms during memory forensics analysis.
- ✗
PTE (Page Table Entry)
Why it's wrong here
PTEs manage virtual-to-physical memory mapping and access permissions. While attackers may manipulate PTEs to mark memory as executable or writable, they do not directly govern the dispatching of system services. SSDT hooking is a higher-level functional redirection compared to the granular manipulation of page table memory permissions.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.