GCFA Introduction to Memory Forensics Practice Question
You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?
⚠ Common exam trap
The trap here is thinking that filescan will show which process has the file open, but filescan only lists file objects in memory without linking them to processes or showing access rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.handles
To find the full path and access type of a file handle, you need a plugin that enumerates handles per process. windows.handles provides exactly that, showing the object name (full path) and granted access for each handle. The other plugins focus on scanning file objects without process association, listing loaded DLLs, or displaying privileges, none of which directly answer the question about a specific handle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
windows.handles
Why this is correct
windows.handles lists the handles open in each process, including the object type, name, and access rights. For a file handle, it shows the full path and the granted access, which directly answers the question about the file's path and access type. This plugin is specifically designed to enumerate handles, making it the correct choice.
- ✗
windows.filescan
Why it's wrong here
windows.filescan scans memory for file objects and can show file paths, but it does not associate them with the processes that have them open. It also does not show access rights. Therefore, it cannot tell you which process has a handle to the file or the access type, so it does not meet the requirement.
- ✗
windows.privs
Why it's wrong here
windows.privs lists the privileges enabled for each process. It does not provide information about file handles or their access types. While privileges are relevant to security analysis, they do not answer the question about a specific file handle's path and access. Thus, this plugin is not appropriate for the scenario.
- ✗
windows.dlllist
Why it's wrong here
windows.dlllist lists the DLLs loaded in a process, not file handles. It would not show a handle to an executable file in a temp directory. This plugin is for analyzing loaded modules, which is unrelated to the task of examining file handles and their access rights.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.