Courseiva

GCFA Introduction to Memory Forensics Practice Question

You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?

⚠ Common exam trap

The trap here is assuming that windows.modules will show all drivers that were ever loaded, when in fact it only shows currently loaded modules and misses unloaded ones.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

windows.modscan

To find drivers that were loaded and then unloaded, you need a plugin that scans kernel pool for module structures rather than relying on the active PsLoadedModuleList. windows.modscan performs exactly that pool scan and can recover residual module metadata, whereas the other plugins either list only active modules or focus on driver objects and IRP hooks, which would not reliably surface an unloaded driver.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    windows.modscan

    Why this is correct

    windows.modscan scans kernel pool memory for module structures and can identify modules that were loaded and later unloaded, because their metadata may remain in pool even after removal from the active module list. This directly addresses the need to find previously loaded drivers that are no longer active, making it the correct plugin for this scenario.

  • ✗

    windows.modules

    Why it's wrong here

    The windows.modules plugin enumerates currently loaded kernel modules by walking the active PsLoadedModuleList. It will not reveal drivers that have been unloaded and removed from that list. In this scenario, the malicious driver is no longer active, so windows.modules would show only legitimate active drivers and miss the unloaded artifact entirely.

  • ✗

    windows.driverscan

    Why it's wrong here

    windows.driverscan scans pool memory for driver objects and can find unlinked drivers, but it does not specifically enumerate previously loaded modules from the kernel module list history. It may miss unloaded drivers that no longer have a driver object in pool, and it is not the plugin designed to list unloaded kernel modules. Therefore it is not the best choice here.

  • ✗

    windows.driverirp

    Why it's wrong here

    windows.driverirp lists the IRP major function pointers for drivers and is used to detect hooking or unusual driver behavior. It does not enumerate unloaded modules. While it can help analyze driver functionality, it will not reveal a driver that has been unloaded, so it does not satisfy the requirement to find previously loaded kernel modules.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.