GCFA Windows Artifact Analysis Practice Question
An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?
⚠ Common exam trap
Test-takers frequently confuse IFEO with standard Run key persistence, which does not redirect execution of other processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
IFEO hijacking involves creating a subkey under Image File Execution Options named after a legitimate executable and setting a Debugger value to a malicious program. This causes Windows to launch the debugger instead of the intended executable. The correct registry path is HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options. Other options are unrelated persistence or forensic artifacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Why this is correct
Image File Execution Options (IFEO) is the correct registry location. Attackers can create a subkey named after a legitimate executable (e.g., notepad.exe) and set a Debugger string value pointing to their malicious binary. When the legitimate executable is launched, Windows starts the debugger instead, achieving persistence and execution. This matches the scenario.
- ✗
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Why it's wrong here
The FileExts key stores user preferences for file associations and how files are opened, but it does not redirect the execution of an executable. It is not used for IFEO hijacking. An attacker would not achieve process redirection by modifying FileExts; they would need to alter the IFEO key instead.
- ✗
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
The Run key is used for autostart persistence, but it does not redirect execution of another executable. IFEO hijacking works by setting a Debugger value under Image File Execution Options for a specific executable. The Run key would simply launch a program at logon, not intercept and redirect a legitimate process, so it is not the correct location for this attack technique.
- ✗
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache
Why it's wrong here
The AppCompatCache (also known as ShimCache) is an artifact that records compatibility information for executed applications. It is not a persistence mechanism and does not contain a Debugger value. Modifying it does not redirect execution. It is used by forensic analysts to determine prior execution, but it is not the registry location for IFEO hijacking.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.