Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?

⚠ Common exam trap

The trap here is seeing the word 'Crypto' in the path and assuming the DLL is a legitimate Windows cryptographic component, when the path is only a plausible-looking masquerade.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This is a persistence mechanism using a masqueraded path and an export invoked via rundll32.

Scheduled tasks that invoke rundll32 against a DLL export located in a user-writable directory are a well-known persistence technique because the signed Microsoft binary performs the loading and evades naive process-name detection. The combination of an author account with no local logon history and a DLL creation timestamp inside the intrusion window confirms this is attacker-planted rather than legitimate cryptographic or installer activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    This is a benign logon script registered by Group Policy for the domain user.

    Why it's wrong here

    Group Policy logon scripts are configured in the user's GPO and reference script files under the SYSVOL share or a defined scripts path, not a DLL in ProgramData invoked by export through rundll32. The absence of a local interactive logon by that account further rules out a logon script, since logon scripts execute during interactive or network logon sessions.

  • ✗

    This indicates a misconfigured application installer that ran as the wrong domain account.

    Why it's wrong here

    A misconfigured installer would typically create its task under a service or system account and place binaries in an application-specific directory, not in a path chosen to resemble a cryptographic store. The 'Register' export invoked through rundll32 is also atypical for installers, which prefer their own setup executables and log their activity in the Application event log.

  • ✗

    This is a legitimate Windows cryptographic component and should be excluded from the investigation.

    Why it's wrong here

    The real Windows cryptographic directory is under 'C:\ProgramData\Microsoft\Crypto\RSA\' for machine keys, but it contains key container data, not executable DLLs registered via rundll32. A DLL named logon.dll with a Register export in that path is not a standard component, and its creation timestamp matching the intrusion window contradicts the legitimate-component explanation.

  • ✓

    This is a persistence mechanism using a masqueraded path and an export invoked via rundll32.

    Why this is correct

    Attackers frequently place DLLs in plausible-looking system directories and register them through rundll32 by export name so the payload executes inside a signed Microsoft binary. The author being a domain user who never logged on locally, combined with the DLL creation time matching the intrusion window, strongly supports a persistence mechanism rather than legitimate software installation.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.