Courseiva

GCFA Introduction to Memory Forensics Practice Question

You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)

⚠ Common exam trap

The trap here is assuming that windows.modules will show all loaded drivers, but a rootkit can unlink its driver so that it no longer appears in that list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.modscan

To detect a driver that has been unlinked from the active module list, you need plugins that scan kernel pool memory for driver-related structures. windows.modscan finds module structures, and windows.driverscan finds driver objects. Together they can reveal a hidden driver that a rootkit has unlinked. The other plugins either list only active modules, focus on IRP hooking, or enumerate callbacks, none of which directly detect unlinked drivers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.modscan

    Why this is correct

    windows.modscan scans kernel pool memory for module structures, which can reveal modules that have been unlinked from the active module list. This is exactly the technique needed to find a hidden driver that a rootkit has removed from PsLoadedModuleList. It can detect the malicious driver's residual metadata, making it a correct choice for this scenario.

  • ✗

    windows.driverirp

    Why it's wrong here

    windows.driverirp lists IRP major function pointers for drivers and is used to detect hooking. While it can reveal a malicious driver if it is already identified, it does not enumerate hidden drivers by scanning memory. It relies on the driver being in the active list or otherwise known. Therefore, it is not suitable for detecting an unlinked driver.

  • ✗

    windows.callbacks

    Why it's wrong here

    windows.callbacks lists kernel callbacks such as those registered for process creation, thread creation, and image loading. It does not enumerate loaded drivers or scan for hidden modules. While a rootkit might register callbacks, this plugin is not designed to detect unlinked drivers, so it is not a correct choice for this scenario.

  • ✗

    windows.modules

    Why it's wrong here

    windows.modules lists the currently loaded kernel modules by walking the active PsLoadedModuleList. If a rootkit has unlinked its driver from this list, windows.modules will not show it. Therefore, this plugin alone cannot detect the hidden driver, though it can provide a baseline of legitimate modules for comparison with other scans.

  • ✓

    windows.driverscan

    Why this is correct

    windows.driverscan scans for driver objects in pool memory and can find drivers that are not present in the active module list. A rootkit that unlinks a driver from the module list may still leave the driver object in pool, so driverscan can detect it. This complements modscan by looking at a different structure, making it a correct choice for detecting hidden drivers.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.