Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?

⚠ Common exam trap

Candidates often guess generic WMI classes like 'Win32_Service' because they associate WMI with persistence. They overlook that 'Win32_Process' is the specific class required for direct, remote command execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Win32_Process, Create

The Win32_Process class, specifically the Create method, allows for the execution of arbitrary commands on remote systems. Incident responders often look for WMI-based process creation events in logs to detect lateral movement. Because WMI is a legitimate administrative tool, distinguishing between normal management traffic and malicious movement is a key challenge for detection and response teams.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Win32_Service, StartService

    Why it's wrong here

    While Win32_Service can be used to start services, it is not the most common method for direct, ephemeral remote command execution. Attackers typically prefer Win32_Process for immediate execution of payloads without the overhead of creating, starting, and deleting a service object on the remote host.

  • ✓

    Win32_Process, Create

    Why this is correct

    The Win32_Process Create method is a standard technique used by attackers to execute commands on remote systems via WMI. It is favored because it does not require a persistent installation, allowing for stealthy lateral movement that is easily integrated into automated post-exploitation scripts and tools.

  • ✗

    Win32_StartupCommand, Create

    Why it's wrong here

    This class is used to manage startup items that run when a user logs in. It is generally used for persistence rather than lateral movement, as it requires a user to log out and log back in to trigger the execution, which is not ideal for real-time pivoting.

  • ✗

    Win32_ScheduledJob, Create

    Why it's wrong here

    While Win32_ScheduledJob can be used for remote execution, it is an older, deprecated method that is often blocked or restricted in modern Windows environments. Most attackers prefer the more reliable and modern Win32_Process Create method for rapid lateral movement across a compromised network.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.