Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

Exhibit

C:\> sc query binPath="C:\Windows\Temp\backdoor.exe"
[SC] OpenService FAILED 1060:

The specified service does not exist.

Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?

⚠ Common exam trap

Candidates often confuse the 'sc query' command with 'sc create'. They assume that because 'query' is used to view services, it is the primary command for all service-related administrative tasks in Windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The command syntax is incorrect for creating a service.

The 'sc query' command is used to inspect existing services, not to register new ones. The attacker attempted to use the query syntax rather than the 'create' command to define the service. Understanding the proper syntax for service manipulation is critical for incident handlers to identify how attackers attempt to achieve persistence via Windows Service Control Manager or other system-level configuration methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service has already been deleted by the system.

    Why it's wrong here

    The error 1060 specifically indicates that the Service Control Manager cannot locate the service in the registry. It does not imply that a service was deleted; rather, it indicates that the command provided was inappropriate for the intended action of creating a new persistent service entry.

  • ✗

    The 'sc' command does not support the 'binPath' argument.

    Why it's wrong here

    The 'sc create' command does indeed support the 'binPath' argument to define the executable path. The issue is that 'sc query' does not take a 'binPath' argument, as it only accepts a service name to identify a service that is already registered within the OS configuration.

  • ✓

    The command syntax is incorrect for creating a service.

    Why this is correct

    The 'sc query' command is designed to retrieve the status of a registered service, not to define a new one. To register a service, the attacker must use 'sc create [ServiceName] binPath=...'. The provided command failed because it was querying for an object that was never defined.

  • ✗

    The user lacks sufficient privileges to query services.

    Why it's wrong here

    Querying services is a low-privilege operation that does not require administrative rights. The failure to find the service is due to the incorrect command structure rather than a lack of permissions. Administrative privileges are only required when attempting to create, delete, or modify service configurations.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.