Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?

⚠ Common exam trap

Candidates often include non-LotL tools like custom malware or unauthorized hacking tools. LotL specifically refers to using pre-installed, trusted system binaries like PowerShell, WMI, or Bitsadmin for malicious purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Utilizing WMI (Windows Management Instrumentation) to execute remote commands.

LotL techniques leverage legitimate, pre-installed administrative tools to perform malicious actions. Because these binaries are signed and expected to be present in the environment, traditional endpoint protection often ignores them. Attackers use these tools for discovery, lateral movement, and execution, effectively hiding their activity in the noise of normal system administration tasks, which makes them highly effective for stealthy operations within a compromised network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Utilizing WMI (Windows Management Instrumentation) to execute remote commands.

    Why this is correct

    WMI is a powerful administrative framework that is frequently abused for remote code execution and lateral movement. Because WMI operations are essential for system management, they often blend in with normal administrative traffic, allowing attackers to maintain persistence and control without installing custom, easily detectable malware binaries.

  • ✗

    Installing a custom kernel-mode rootkit for persistence.

    Why it's wrong here

    A rootkit is a custom malicious tool, not a legitimate system utility. LotL specifically refers to using native, pre-installed tools. Installing custom malicious drivers would trigger signature-based security alerts and is not considered a LotL technique, as it introduces external code that is not part of the standard Windows installation.

  • ✓

    Using Bitsadmin to download external payloads.

    Why this is correct

    Bitsadmin is a native Windows tool for managing Background Intelligent Transfer Service jobs. Attackers use it to download payloads stealthily because it is a trusted system utility. Using legitimate administrative tools for unauthorized file transfers is a hallmark of LotL activity that evades simple binary-based blocking mechanisms.

  • ✓

    Executing scripts via PowerShell to gather system information.

    Why this is correct

    PowerShell is a standard administrative environment in Windows. Attackers leverage it to perform discovery, enumeration, and data collection. Since PowerShell is used daily by IT staff, malicious use is often overlooked by standard security monitoring, provided the attacker avoids triggering specific suspicious script block signatures or behavioral alerts.

  • ✗

    Running a custom C++ backdoor compiled on the target.

    Why it's wrong here

    Compiling custom code on a target system introduces a foreign binary. LotL techniques focus on using what is already there. While compiling code might evade static binary analysis, it is not a LotL technique, as the attacker is introducing their own tools rather than utilizing pre-installed OS utilities.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.