Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

During an investigation, you discover that an attacker used the Windows utility 'schtasks' to create a scheduled task on a compromised endpoint. The task is configured to run a malicious executable every time a user logs on. Which of the following best describes the attacker's primary goal with this action?

⚠ Common exam trap

The trap here is assuming that any scheduled task is for privilege escalation, when the logon trigger specifically points to persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To maintain persistence on the compromised host.

Creating a scheduled task that runs at user logon is a classic persistence technique. It ensures the attacker's payload executes automatically after a reboot or when a user logs in, allowing the attacker to maintain a foothold. While the executable could perform other actions, the primary goal of the scheduled task is to establish persistence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To escalate privileges by running the executable as SYSTEM.

    Why it's wrong here

    While scheduled tasks can be configured to run with highest privileges, the scenario does not specify that the task runs as SYSTEM. The trigger is set for user logon, which typically runs in the user's context. The primary goal is persistence, not privilege escalation, unless explicitly configured otherwise.

  • ✗

    To exfiltrate data to an external command and control server.

    Why it's wrong here

    Data exfiltration would involve network communication to send data out. While the executable could perform exfiltration, the scheduled task itself is a trigger mechanism. The primary goal of creating the task is to ensure execution, not directly to exfiltrate data. The task's action could be anything, but persistence is the overarching objective.

  • ✗

    To disable antivirus software on the endpoint.

    Why it's wrong here

    Disabling antivirus is a defense evasion technique, but the scheduled task described does not inherently do that. The task runs a malicious executable; its purpose could be anything, but the use of a logon trigger strongly indicates persistence. Without additional context, assuming antivirus disabling is speculative.

  • ✓

    To maintain persistence on the compromised host.

    Why this is correct

    Scheduled tasks are a common persistence mechanism. By configuring a task to run at logon, the attacker ensures the malicious executable executes automatically after a reboot or user session. This allows the attacker to maintain access without needing to re-exploit the system.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.