Courseiva
Security Operations →hardMultiple Select

CS0-003 Security Operations Practice Question

During a threat hunt, an analyst uses Velociraptor to collect forensic artifacts from endpoints. Which THREE of the following artifacts are most useful for detecting persistence mechanisms?

⚠ Common exam trap

CS0-004 often tests the distinction between persistence artifacts and other forensic data; candidates may incorrectly select network-related artifacts like ARP cache or benign system information like installed updates, confusing general forensic value with persistence detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled tasks

Scheduled tasks (B) are a classic persistence mechanism because attackers can register a task to execute malware at logon, startup, or on a recurring schedule, and Velociraptor can enumerate them via artifacts like Windows.System.TaskScheduler. Service configuration (D) is equally relevant since creating or modifying a Windows service (e.g., with a malicious ImagePath or auto-start type) allows code to run at boot under SYSTEM privileges. Registry Run keys (E) such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents are a well-known autostart location that malware abuses for persistence at user logon. The list of installed updates (A) is useful for patch-level and vulnerability assessment, not for identifying persistence, and the ARP cache (C) only shows recent IP-to-MAC mappings, which is network-state data rather than a persistence indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List of installed updates

    Why it's wrong here

    An installed updates list, typically from Windows Update, WSUS, or a package manager, records patch history and does not contain any auto-start extension points. Updates alter system binaries and are scheduled by Windows Update services, but simply knowing a patch is installed does not reveal a persistence mechanism. Attackers may abuse update infrastructure or overwrite update binaries, but the list itself is not an execution artifact for threat hunting persistence. Therefore, while useful for vulnerability management, this collection is not relevant for identifying attacker persistence.

  • ✓

    Scheduled tasks

    Why this is correct

    Scheduled tasks are a native Windows mechanism that can trigger a binary or script when a user logs on, at system startup, or at regular intervals. Attackers routinely create named or hidden tasks to rerun malware or maintain command-and-control, and these tasks survive a reboot (unless disabled). Because the task description, action, triggers, and run-as user are all stored in the Task Scheduler database, examining it with Velociraptor can reveal suspicious persistence. This makes scheduled tasks an essential artifact in any threat hunt.

  • ✗

    ARP cache

    Why it's wrong here

    The ARP cache is a volatile protocol-level mapping between IPv4 addresses and MAC addresses for hosts on the local network, and it is populated dynamically as traffic is sent. It contains no executable code, no logon triggers, and no boot-time configuration, so it cannot serve as a persistence mechanism. While clearing or poisoning the ARP cache can aid in network attacks or pivoting, the cache contents themselves do not re-launch code after reboot. Thus, it is a red herring for identifying how malware maintains persistence.

  • ✓

    Service configuration

    Why this is correct

    Windows services are registered under the Service Control Manager and are configured to start automatically when the system boots, often under LocalSystem or another privileged account. An attacker can create a new service pointing to a malicious executable (e.g., via `sc create` or by writing to `HKLM\SYSTEM\CurrentControlSet\Services`) and set its start type to AUTO_START to gain persistence. Collecting service configurations enables an analyst to spot unusual image paths or services named to imitate legitimate software, making this artifact highly relevant for persistence detection.

  • ✓

    Registry Run keys

    Why this is correct

    Run keys such as `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run` specify commands that automatically execute when a user logs into the system. Attackers frequently add malicious entry names and binary paths to these keys, and the effect is limited to logon, not boot (for HKCU) or applies to all users. Velociraptor can collect and parse these values to identify unexpected autostarts, making them a classic persistence artifact. The existence of a Run key is a strong indicator for persistence.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.