GPEN Command and Control Practice Question
During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?
⚠ Common exam trap
Watch out — candidates often confuse user-logon persistence (Run keys, onlogon tasks) with system-boot persistence (services), which does not require a user to log in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto
Creating a Windows service with sc.exe is a reliable method for achieving persistence because services can be configured to start automatically at boot, independent of user logon. The command must use the correct syntax with spaces after 'binPath=' and 'start='. Other options either rely on user logon or use invalid syntax, failing to meet the requirement of persistence across reboots without user interaction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
wmic service create name='Updater' path='C:\Windows\Temp\payload.exe' startmode='Auto'
Why it's wrong here
WMIC does not have a 'service create' subcommand. The correct WMIC syntax for service creation is not supported; wmic can manage existing services but cannot create new ones. Therefore, this command would fail. Although WMIC can be used for other persistence methods, it is not a valid way to create a Windows service, making this option incorrect.
- ✗
schtasks /create /tn "Updater" /tr "C:\Windows\Temp\payload.exe" /sc onlogon
Why it's wrong here
This command creates a scheduled task that runs only when a user logs on, not at system startup. If the compromised host reboots and no user logs in, the payload will not execute, breaking persistence. While scheduled tasks are a valid persistence method, the 'onlogon' trigger does not meet the requirement of surviving reboot without user interaction, as specified in the scenario.
- ✓
sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto
Why this is correct
This command uses the Windows Service Control Manager to create a new service named 'Updater' that runs the specified payload executable automatically at system startup. The syntax with spaces after equals signs is required for sc.exe. This achieves persistence because the service will start each time Windows boots, maintaining the C2 channel without relying on user logon.
- ✗
reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Windows\Temp\payload.exe"
Why it's wrong here
This command adds a registry value to the Run key, which executes the payload when a user logs on. Like the scheduled task with onlogon, it requires a user to log in after reboot, so it does not provide persistence if the system restarts and no one logs in. The scenario explicitly requires persistence even after the user logs off or the system reboots, making this insufficient.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.