Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?

⚠ Common exam trap

Candidates often confuse service persistence with Run key persistence, but services are stored in the SYSTEM hive under CurrentControlSet\Services, not in the SOFTWARE hive's Run keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\SYSTEM\CurrentControlSet\Services

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has its own subkey containing values like ImagePath, which specifies the executable to run, and Start, which determines the start type. Investigating this key allows you to identify malicious services and their executables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HKLM\SYSTEM\CurrentControlSet\Services

    Why this is correct

    This registry key contains subkeys for each installed service. Each service subkey includes values such as ImagePath, which points to the executable, and Start, which defines when the service starts. Examining this key will reveal the malicious service's configuration, including the path to the malicious executable.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    Why it's wrong here

    The Winlogon key is used for configuring user logon processes, such as Shell and Userinit. It is a persistence location for logon scripts or custom shells, but not for Windows services. Services are not configured here.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    The Run key is used for autostart programs that execute when a user logs on. It does not store service configurations. Services are managed under a different registry hive. This key is a common persistence location but not for services.

  • ✗

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    This key is the per-user equivalent of the Run key and is used for autostart programs when the specific user logs on. It does not store service configurations. Services are system-wide and stored in the SYSTEM hive, not in HKCU.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.