GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An incident responder is analyzing a compromised Windows host and discovers that the attacker used the built-in 'sc.exe' utility to create a new service named 'WinDefendHelper' with a binary path pointing to a file in C:\Users\Public\Documents. The service was set to start automatically and the attacker then deleted the original dropper executable. Which persistence mechanism has the attacker implemented, and what is the most reliable detection artifact?
⚠ Common exam trap
The trap here is focusing on the deleted dropper file rather than the persistent service registration, which remains in the registry and event logs even after the executable is removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A new Windows service was created; detection should focus on Event ID 7045 in the System log and registry keys under HKLM\SYSTEM\CurrentControlSet\Services.
Using sc.exe to create a new auto-start service is a classic Windows persistence technique. Event ID 7045 in the System log records the service installation with its name, image path, and start type, while the registry key under HKLM\SYSTEM\CurrentControlSet\Services stores the persistent configuration. Together these artifacts survive deletion of the original dropper and provide reliable detection evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A WMI event subscription was created; detection should focus on the __EventFilter and __EventConsumer classes in the root\subscription namespace.
Why it's wrong here
WMI event subscriptions use __EventFilter and __EventConsumer classes and are created via wmic or PowerShell, not sc.exe. The scenario explicitly shows sc.exe creating a service, so the WMI subscription artifacts would not be present. Investigating the root\subscription namespace would yield no evidence of this specific persistence mechanism.
- ✗
A startup folder shortcut was placed; detection should focus on file creation events in the user's Startup directory.
Why it's wrong here
Startup folder persistence involves dropping a shortcut or executable into the user's Startup directory, which triggers on user logon. The scenario describes a service created with sc.exe and set to start automatically, which runs at system boot under the service control manager, not at user logon. The Startup folder would not contain this artifact.
- ✓
A new Windows service was created; detection should focus on Event ID 7045 in the System log and registry keys under HKLM\SYSTEM\CurrentControlSet\Services.
Why this is correct
Creating a service with sc.exe generates Event ID 7045 in the System event log, recording the service name, image path, and start type. The corresponding registry key under HKLM\SYSTEM\CurrentControlSet\Services persists the configuration. Even if the dropper is deleted, the service entry and its event log record remain, making these the most reliable detection artifacts for this persistence technique.
- ✗
A scheduled task was registered; detection should focus on the TaskCache registry key and Event ID 4698 in the Security log.
Why it's wrong here
Scheduled task creation uses schtasks.exe or the Task Scheduler COM interface and generates Event ID 4698. The scenario describes sc.exe creating a service, which is a distinct persistence mechanism. While scheduled tasks are a common persistence method, the specific tool and resulting artifacts described here point to service creation, not task registration.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.