GCFA Enterprise Environment Incident Response Practice Question
During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?
⚠ Common exam trap
Candidates often confuse service persistence with Run key persistence, but services are stored in the SYSTEM hive under CurrentControlSet\Services, not in the SOFTWARE hive's Run keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\SYSTEM\CurrentControlSet\Services
Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has its own subkey containing values like ImagePath, which specifies the executable to run, and Start, which determines the start type. Investigating this key allows you to identify malicious services and their executables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HKLM\SYSTEM\CurrentControlSet\Services
Why this is correct
This registry key contains subkeys for each installed service. Each service subkey includes values such as ImagePath, which points to the executable, and Start, which defines when the service starts. Examining this key will reveal the malicious service's configuration, including the path to the malicious executable.
- ✗
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Why it's wrong here
The Winlogon key is used for configuring user logon processes, such as Shell and Userinit. It is a persistence location for logon scripts or custom shells, but not for Windows services. Services are not configured here.
- ✗
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
The Run key is used for autostart programs that execute when a user logs on. It does not store service configurations. Services are managed under a different registry hive. This key is a common persistence location but not for services.
- ✗
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
This key is the per-user equivalent of the Run key and is used for autostart programs when the specific user logs on. It does not store service configurations. Services are system-wide and stored in the SYSTEM hive, not in HKCU.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.