Courseiva

GCFA Enterprise Environment Incident Response Practice Question

Which technique is commonly used by attackers to maintain persistence on a Windows system that specifically targets the login process?

⚠ Common exam trap

Candidates often confuse persistence with privilege escalation. While SSPs facilitate both, their specific role in the authentication chain makes them a primary target for stealthy, boot-time persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Loading a malicious Security Support Provider (SSP).

The 'Authentication Packages' or 'SSP' (Security Support Provider) mechanism is a common target for persistence. By loading a malicious DLL as an SSP, the attacker ensures that their code is loaded into the Local Security Authority Subsystem Service (LSASS) process every time the system boots. This grants the attacker deep-level persistence and the ability to capture credentials as they are processed, making it a highly effective and stealthy technique for maintaining long-term access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adding a shortcut to the Startup folder.

    Why it's wrong here

    While adding a shortcut to the Startup folder provides persistence, it is a very low-level and easily detected technique. Modern security tools and user awareness typically identify startup items quickly. It does not target the login process itself, making it less sophisticated than loading malicious SSPs into the LSASS process.

  • ✗

    Modifying the Windows registry Run keys.

    Why it's wrong here

    Registry Run keys are a common persistence mechanism, but they run only after a user logs in. They do not target the core authentication process of the operating system. While effective for basic persistence, they lack the stealth and privileged access provided by hooking into the login process via SSPs.

  • ✓

    Loading a malicious Security Support Provider (SSP).

    Why this is correct

    Loading a custom SSP via the registry allows the malicious DLL to be loaded into the LSASS process at boot. This provides the attacker with persistence that is integrated into the Windows authentication flow, allowing them to hook system functions and monitor credentials as they are entered by users.

  • ✗

    Installing a malicious browser extension.

    Why it's wrong here

    Browser extensions provide persistence only within the context of the web browser. They do not grant the attacker control over the operating system's authentication process or provide machine-wide persistence. This technique is limited in scope and does not achieve the same level of system-level persistence as targeting the LSASS.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.