Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

An incident responder is examining a Windows Server 2016 system that is suspected of being compromised. The responder runs 'net user' and sees a new account named 'Support' that was not there before. The account is a member of the local Administrators group. The responder checks the Security event log and sees Event ID 4720 (A user account was created) followed by Event ID 4732 (A member was added to a security-enabled local group). The responder also notices that the account has never been logged into. Which post-exploitation technique does this represent?

⚠ Common exam trap

The trap here is overlooking the significance of a new local account with administrative privileges and no logon activity; it is a clear persistence mechanism, not a credential theft or domain-level attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Backdoor user account creation

The creation of a new local account and its addition to the Administrators group is a backdoor user account creation technique. Attackers use this to maintain persistent access. The event IDs 4720 and 4732 are key indicators. This account, never logged into, serves as a dormant backdoor that can be activated later.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting is an attack against service accounts in Active Directory, where an attacker requests service tickets and cracks them offline. It does not involve creating local user accounts or modifying local groups. The scenario describes local account creation and group membership changes, which are unrelated to Kerberoasting. Therefore, this option is incorrect.

  • ✗

    DCSync

    Why it's wrong here

    DCSync is a technique where an attacker impersonates a domain controller to replicate password hashes from Active Directory. It does not create local user accounts. The scenario shows local account creation on a server, not domain replication. Thus, DCSync is not applicable here, and the event IDs would be different.

  • ✓

    Backdoor user account creation

    Why this is correct

    The creation of a new local account and its addition to the Administrators group is a classic backdoor technique. Attackers create such accounts to maintain access even if their initial foothold is removed. The fact that the account has never been logged into suggests it is a dormant backdoor, waiting to be used. Event IDs 4720 and 4732 confirm this activity.

  • ✗

    Pass-the-Hash

    Why it's wrong here

    Pass-the-Hash involves using a captured NTLM hash to authenticate without knowing the plaintext password. It does not create new accounts. The scenario describes the creation of a new local account, which is a persistence mechanism, not an authentication bypass. Therefore, Pass-the-Hash is not the correct technique.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.