Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An enterprise incident responder is analyzing a compromised Windows 10 workstation. The attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with the action 'C:\Windows\Temp\svchost.exe'. However, the file svchost.exe is not present in that directory. Which of the following best explains why the task still appears and what should the responder do next?

⚠ Common exam trap

The trap here is assuming that a scheduled task with a missing executable is automatically harmless or will self-remove.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file may have been deleted by the attacker or antivirus; the task definition remains in the registry and should be examined and removed if malicious.

Scheduled tasks persist in the registry and on disk even if the referenced executable is missing. The attacker may have deleted the executable to hinder analysis, but the task definition remains and can be used to re-establish persistence if the file is restored. The responder must examine the task's XML, registry entries, and creation time, then remove it if malicious. This ensures the persistence mechanism is fully eradicated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The task is likely a legitimate Windows component; svchost.exe in Temp is normal. The responder should ignore it.

    Why it's wrong here

    Legitimate svchost.exe resides in System32 and is never located in C:\Windows\Temp. Its presence in Temp is a strong indicator of malicious activity. Ignoring it would allow the attacker to maintain persistence. The responder must treat this as suspicious and investigate the task's origin, creation time, and associated registry artifacts.

  • ✗

    The task is a ghost entry; it will be removed after a reboot. No further action is needed.

    Why it's wrong here

    Scheduled tasks are stored in the registry and on disk (in System32\Tasks) and persist across reboots unless explicitly deleted. A missing executable does not cause the task to be automatically removed; it will simply fail to run. Assuming it is a ghost entry could leave a persistence mechanism in place, allowing the attacker to replace the executable later. The responder must investigate further.

  • ✗

    The task was created by a Group Policy Object (GPO); it will be recreated on next policy refresh. The responder should check GPOs.

    Why it's wrong here

    While GPOs can create scheduled tasks, they typically deploy tasks with legitimate paths and signed binaries. The path C:\Windows\Temp\svchost.exe is highly suspicious and not typical for GPO-deployed tasks. Assuming GPO involvement without evidence could misdirect the investigation. The responder should first verify the task's source via registry and event logs, and only then consider GPOs if indicated.

  • ✓

    The file may have been deleted by the attacker or antivirus; the task definition remains in the registry and should be examined and removed if malicious.

    Why this is correct

    Scheduled tasks are defined in the registry under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache and also have corresponding files in System32\Tasks. Even if the executable is missing, the task definition persists. The attacker might have deleted the file to evade detection, or antivirus may have quarantined it. The responder should examine the task's XML definition, check for related registry keys, and remove the task if it is malicious to eliminate persistence.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.