Courseiva
Windows Artifact Analysis →mediumMultiple Choice

GCFA Windows Artifact Analysis Practice Question

An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?

⚠ Common exam trap

The trap here is assuming that service information is stored in the Run key or other autostart locations, which are for user-level programs rather than system services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\SYSTEM\CurrentControlSet\Services

The Services registry key stores configuration data for every Windows service, including the ImagePath value that points to the executable and the ObjectName value that specifies the account. Examining this key allows the analyst to identify the malicious service's original path and the security context it uses, which is critical for understanding persistence and privilege level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost

    Why it's wrong here

    This key lists services that are hosted in Svchost.exe, but it does not contain the executable path or account for each service. The actual configuration for those services is still stored under the Services key. Thus, it would not provide the original path or account information needed.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    The Run key is used for autostarting programs at user logon, not for service configuration. It does not store service executable paths or service account information. Therefore, it would not provide the specific details about the malicious service's original path or the account it runs under.

  • ✗

    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager

    Why it's wrong here

    This key contains information about pending file rename operations, known DLLs, and other session manager settings. It does not store service configurations. An analyst looking here would not find the service executable path or the account it runs under, making it an incorrect choice for this scenario.

  • ✓

    HKLM\SYSTEM\CurrentControlSet\Services

    Why this is correct

    Each subkey under HKLM\SYSTEM\CurrentControlSet\Services represents an installed service and contains values such as ImagePath (the executable path) and ObjectName (the account the service runs under). This is the primary location for service configuration, making it the correct choice for identifying the original path and account.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.