GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?
⚠ Common exam trap
The trap here is treating the presence of a SYSTEM-owned scheduled task in a Microsoft vendor namespace as inherently suspicious, when this is exactly how legitimate vendor updaters are deployed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The task appears legitimate, but the analyst should verify the binary's digital signature and compare the creation timestamp against the Edge installation baseline.
Every attribute of the task — its folder, name, executable, argument, owner, and modification time — is consistent with the Edge updater installed on the server. Scheduled tasks are nonetheless a popular persistence vector, so the correct posture is to corroborate with signature verification and timestamp comparison against the known Edge installation baseline before clearing it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The task appears legitimate, but the analyst should verify the binary's digital signature and compare the creation timestamp against the Edge installation baseline.
Why this is correct
All observed attributes — namespace, executable path, argument, owner, and timestamp — align with a standard Edge updater installation. Because scheduled tasks are a common persistence mechanism, best practice is to confirm the binary is signed by Microsoft and that the timestamp matches the known Edge install baseline. This combination of corroboration supports a benign classification while still applying forensic rigor.
- ✗
The task is definitely a persistence mechanism because it runs at logon and uses the '/ua' switch, which is undocumented.
Why it's wrong here
The '/ua' switch is a documented Edge updater flag that instructs the updater to run in user-agnostic mode, and the task does not necessarily trigger at every logon. Even if it triggered at logon, that alone does not make a task malicious, since many legitimate maintenance tasks run at logon. Calling the switch undocumented and therefore malicious is inaccurate.
- ✗
The task is malicious persistence because SYSTEM-created tasks in the Microsoft namespace are not legitimate.
Why it's wrong here
Microsoft and many third-party vendors routinely create scheduled tasks under their own subfolders in Task Scheduler Library, and these tasks often run as SYSTEM. The 'Microsoft\EdgeUpdate' path is the legitimate namespace used by the Edge updater. Treating every SYSTEM-owned task as malicious would produce false positives and misclassify ordinary vendor maintenance activity.
- ✗
The task is suspicious because the executable path uses the 'Program Files (x86)' directory on a 64-bit server.
Why it's wrong here
Edge's updater is a 32-bit component and is intentionally installed under 'Program Files (x86)' even on 64-bit Windows. The presence of the (x86) path is consistent with a normal Edge installation and is not, by itself, an indicator of compromise. Analysts should verify the binary's signature and hash rather than judging solely on directory naming.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.