GCFA Enterprise Environment Incident Response Practice Question
During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?
⚠ Common exam trap
The trap here is assuming that the Run key or event logs provide service configuration details, when only the SYSTEM hive's Services key contains the authoritative ImagePath and Start values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SYSTEM registry hive, specifically the Services key under CurrentControlSet
The SYSTEM registry hive stores all service configurations under CurrentControlSet\Services, including the binary path, start type, and account. This makes it the definitive artifact for identifying malicious service persistence. Other artifacts like the Run key, $MFT, or event logs may provide context but do not contain the full service configuration needed for triage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The SYSTEM registry hive, specifically the Services key under CurrentControlSet
Why this is correct
The SYSTEM registry hive contains the Services subkey under CurrentControlSet, which stores service configuration including the ImagePath, Start type, and ObjectName. This is the authoritative source for service persistence. Examining it directly reveals malicious services even if the Service Control Manager database is cleared or the service is set to disabled, making it the first artifact to check.
- ✗
The Windows Event Log Security.evtx for event ID 4697
Why it's wrong here
Event ID 4697 indicates that a service was installed, but it may not be logged if audit policy is not configured, and it does not provide the current configuration or binary path. It is a useful corroborating artifact but not the primary source for service details. Relying on it alone could miss services installed before auditing was enabled.
- ✗
The SOFTWARE registry hive, specifically the Microsoft\Windows\CurrentVersion\Run key
Why it's wrong here
The Run key in the SOFTWARE hive is used for autostarting programs at user logon, not for Windows services. While it is a persistence mechanism, it does not contain service configuration data such as ImagePath or Start type. Investigating it would miss service-based persistence and lead the responder down the wrong path for this specific triage goal.
- ✗
The NTFS $MFT to identify recently created executable files in System32
Why it's wrong here
The $MFT records file metadata and can show timestamps of executables, but it does not link a file to a service configuration. It cannot reveal the service name, start type, or which binary is registered as a service. While useful for timeline analysis, it is not the first artifact to determine service persistence details.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.