GCFA Introduction to Memory Forensics Practice Question
You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?
⚠ Common exam trap
The trap here is thinking that the registry hivelist will give you the OS version quickly, when in fact you would need to parse the registry separately and it is not a direct memory analysis plugin for OS identification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
windows.info
To identify the operating system version and service pack from a memory image, you need a plugin that reads kernel version data. windows.info extracts this directly from the kernel structures in memory, providing the build number and service pack level. The other plugins focus on registry hives, process listing, and command lines, none of which directly report the OS version in a concise manner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
windows.cmdline
Why it's wrong here
windows.cmdline displays the command-line arguments for processes. It does not report OS version or service pack information. While command lines can reveal installed applications or services, they are not a source for the kernel version. This plugin is unrelated to the task of identifying the operating system from memory.
- ✗
windows.registry.hivelist
Why it's wrong here
windows.registry.hivelist lists the registry hives loaded in memory but does not directly report the operating system version or service pack. While registry hives contain OS version information, you would need to parse specific keys, and hivelist itself does not provide a concise summary. It is not the most direct plugin for identifying the OS version from memory.
- ✗
windows.pslist
Why it's wrong here
windows.pslist enumerates running processes and shows their PIDs and names. It does not provide operating system version details. Although the presence of certain processes might hint at the OS version, it is not a reliable or direct method. Therefore, it is not the correct plugin for determining the OS version from a memory image.
- ✓
windows.info
Why this is correct
windows.info reads the kernel's version information and other basic system details directly from the memory image. It displays the major and minor version, build number, service pack, and architecture, which are essential for selecting the correct symbol table or profile. This plugin is specifically designed to provide OS identification from memory, making it the correct choice.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.