Courseiva
Command and Control →mediumMultiple Choice

GPEN Command and Control Practice Question

During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?

⚠ Common exam trap

Watch out — candidates often confuse user-logon persistence (Run keys, onlogon tasks) with system-boot persistence (services), which does not require a user to log in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto

Creating a Windows service with sc.exe is a reliable method for achieving persistence because services can be configured to start automatically at boot, independent of user logon. The command must use the correct syntax with spaces after 'binPath=' and 'start='. Other options either rely on user logon or use invalid syntax, failing to meet the requirement of persistence across reboots without user interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    wmic service create name='Updater' path='C:\Windows\Temp\payload.exe' startmode='Auto'

    Why it's wrong here

    WMIC does not have a 'service create' subcommand. The correct WMIC syntax for service creation is not supported; wmic can manage existing services but cannot create new ones. Therefore, this command would fail. Although WMIC can be used for other persistence methods, it is not a valid way to create a Windows service, making this option incorrect.

  • ✗

    schtasks /create /tn "Updater" /tr "C:\Windows\Temp\payload.exe" /sc onlogon

    Why it's wrong here

    This command creates a scheduled task that runs only when a user logs on, not at system startup. If the compromised host reboots and no user logs in, the payload will not execute, breaking persistence. While scheduled tasks are a valid persistence method, the 'onlogon' trigger does not meet the requirement of surviving reboot without user interaction, as specified in the scenario.

  • ✓

    sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto

    Why this is correct

    This command uses the Windows Service Control Manager to create a new service named 'Updater' that runs the specified payload executable automatically at system startup. The syntax with spaces after equals signs is required for sc.exe. This achieves persistence because the service will start each time Windows boots, maintaining the C2 channel without relying on user logon.

  • ✗

    reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Windows\Temp\payload.exe"

    Why it's wrong here

    This command adds a registry value to the Run key, which executes the payload when a user logs on. Like the scheduled task with onlogon, it requires a user to log in after reboot, so it does not provide persistence if the system restarts and no one logs in. The scenario explicitly requires persistence even after the user logs off or the system reboots, making this insufficient.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.