Courseiva

GPEN Domain Escalation and Persistence Practice Question

Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?

⚠ Common exam trap

Candidates often think scheduled tasks are only for running things at specific times, failing to realize they offer granular control over triggers like idle time or network connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They allow for granular control over execution triggers.

Scheduled tasks are highly configurable, allowing attackers to define specific triggers, user contexts, and repeat intervals. They are natively supported by Windows and appear as legitimate tasks, making them appear less suspicious than custom registry modifications. The ability to run tasks as SYSTEM or as a specific user provides attackers with flexibility in executing their payloads while maintaining a low profile within the system's management tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They automatically bypass all firewall rules.

    Why it's wrong here

    Scheduled tasks are execution mechanisms and have no effect on network-level firewall rules. If the task requires network access, it must still comply with existing system firewall policies. This is a common misconception, as persistence mechanisms do not grant special permissions for bypassing network security controls or firewall configurations.

  • ✓

    They allow for granular control over execution triggers.

    Why this is correct

    Scheduled tasks offer diverse triggers like system startup, user login, or specific time intervals. This granularity allows attackers to time their activity for periods of low system usage or to ensure their code runs reliably after reboots, maximizing the longevity of the persistent connection to the target system.

  • ✗

    They hide the task from the Task Scheduler GUI.

    Why it's wrong here

    Scheduled tasks are visible in the Task Scheduler GUI. While some advanced techniques can hide tasks from basic views, the standard functionality does not provide this capability. If a task is visible, it is likely to be discovered by a careful administrator checking the system's scheduled task repository.

  • ✗

    They are the only way to execute scripts at boot.

    Why it's wrong here

    There are numerous ways to execute scripts at boot, including the Run registry keys, startup folders, and system services. Scheduled tasks are just one of many options available to an attacker. Claiming they are the only method is factually incorrect and ignores the breadth of persistence techniques available.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.