GCIH Endpoint Attack and Pivoting Practice Question
An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?
⚠ Common exam trap
Candidates often guess generic WMI classes like 'Win32_Service' because they associate WMI with persistence. They overlook that 'Win32_Process' is the specific class required for direct, remote command execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Win32_Process, Create
The Win32_Process class, specifically the Create method, allows for the execution of arbitrary commands on remote systems. Incident responders often look for WMI-based process creation events in logs to detect lateral movement. Because WMI is a legitimate administrative tool, distinguishing between normal management traffic and malicious movement is a key challenge for detection and response teams.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Win32_Service, StartService
Why it's wrong here
While Win32_Service can be used to start services, it is not the most common method for direct, ephemeral remote command execution. Attackers typically prefer Win32_Process for immediate execution of payloads without the overhead of creating, starting, and deleting a service object on the remote host.
- ✓
Win32_Process, Create
Why this is correct
The Win32_Process Create method is a standard technique used by attackers to execute commands on remote systems via WMI. It is favored because it does not require a persistent installation, allowing for stealthy lateral movement that is easily integrated into automated post-exploitation scripts and tools.
- ✗
Win32_StartupCommand, Create
Why it's wrong here
This class is used to manage startup items that run when a user logs in. It is generally used for persistence rather than lateral movement, as it requires a user to log out and log back in to trigger the execution, which is not ideal for real-time pivoting.
- ✗
Win32_ScheduledJob, Create
Why it's wrong here
While Win32_ScheduledJob can be used for remote execution, it is an older, deprecated method that is often blocked or restricted in modern Windows environments. Most attackers prefer the more reliable and modern Win32_Process Create method for rapid lateral movement across a compromised network.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.