Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?

⚠ Common exam trap

The trap here is assuming that the Run key or event logs provide service configuration details, when only the SYSTEM hive's Services key contains the authoritative ImagePath and Start values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SYSTEM registry hive, specifically the Services key under CurrentControlSet

The SYSTEM registry hive stores all service configurations under CurrentControlSet\Services, including the binary path, start type, and account. This makes it the definitive artifact for identifying malicious service persistence. Other artifacts like the Run key, $MFT, or event logs may provide context but do not contain the full service configuration needed for triage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SYSTEM registry hive, specifically the Services key under CurrentControlSet

    Why this is correct

    The SYSTEM registry hive contains the Services subkey under CurrentControlSet, which stores service configuration including the ImagePath, Start type, and ObjectName. This is the authoritative source for service persistence. Examining it directly reveals malicious services even if the Service Control Manager database is cleared or the service is set to disabled, making it the first artifact to check.

  • ✗

    The Windows Event Log Security.evtx for event ID 4697

    Why it's wrong here

    Event ID 4697 indicates that a service was installed, but it may not be logged if audit policy is not configured, and it does not provide the current configuration or binary path. It is a useful corroborating artifact but not the primary source for service details. Relying on it alone could miss services installed before auditing was enabled.

  • ✗

    The SOFTWARE registry hive, specifically the Microsoft\Windows\CurrentVersion\Run key

    Why it's wrong here

    The Run key in the SOFTWARE hive is used for autostarting programs at user logon, not for Windows services. While it is a persistence mechanism, it does not contain service configuration data such as ImagePath or Start type. Investigating it would miss service-based persistence and lead the responder down the wrong path for this specific triage goal.

  • ✗

    The NTFS $MFT to identify recently created executable files in System32

    Why it's wrong here

    The $MFT records file metadata and can show timestamps of executables, but it does not link a file to a service configuration. It cannot reveal the service name, start type, or which binary is registered as a service. While useful for timeline analysis, it is not the first artifact to determine service persistence details.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.