Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?

⚠ Common exam trap

It's easy for candidates to confuse registry autostart locations such as Run or Winlogon Shell with scheduled tasks, when only the Task Scheduler store holds task actions and triggers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file C:\Windows\System32\Tasks\<TaskName> in the Task Scheduler store

Scheduled tasks are defined as XML files in the Task Scheduler store under C:\Windows\System32\Tasks, and each file includes the task's Triggers and Actions. A logon trigger with an action launching a suspicious binary is exactly the persistence configuration described, so inspecting that XML file directly reveals both the executable and the trigger that causes it to run at logon.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The file C:\Windows\System32\Tasks\<TaskName> in the Task Scheduler store

    Why this is correct

    The Task Scheduler stores each task as an XML file under C:\Windows\System32\Tasks, named after the task path. That XML contains the Actions (the executable and arguments) and Triggers, including logon triggers, so examining it directly reveals the suspicious binary and the logon trigger configured for persistence.

  • ✗

    The Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders key in the SOFTWARE hive

    Why it's wrong here

    User Shell Folders defines paths for user shell folders such as Desktop and Start Menu. It is unrelated to scheduled task configuration and would not contain any information about task actions, triggers, or the suspicious binary referenced in the scenario.

  • ✗

    The Microsoft\Windows NT\CurrentVersion\Winlogon key's Shell value in the SOFTWARE hive

    Why it's wrong here

    The Winlogon Shell value specifies the user shell program launched after logon and can be abused for persistence, but it is not a scheduled task mechanism. It would not contain task actions or triggers, so it cannot identify the scheduled task described in the scenario.

  • ✗

    The Software\Microsoft\Windows\CurrentVersion\Run key in the NTUSER.DAT hive

    Why it's wrong here

    The Run key provides persistence at logon but is a registry autostart mechanism, not a scheduled task. It would show entries that launch programs at logon, but it would not contain the task's trigger and action configuration, so it cannot answer a question specifically about a scheduled task.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.