Courseiva

GPEN Domain Escalation and Persistence Practice Question

Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?

⚠ Common exam trap

Candidates often suggest common techniques like Run keys or startup folders, overlooking that these are heavily monitored. WMI is chosen specifically for its ability to operate stealthily without registry modifications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating a WMI event subscription for system events.

Persistence is often detected via common registry keys like Run or RunOnce. Using Windows Management Instrumentation (WMI) event subscriptions allows for persistence that is harder to detect. By creating an EventFilter and EventConsumer, an attacker can trigger a malicious script based on system events, such as a specific time or system uptime, bypassing traditional registry-based forensic analysis and providing a robust, fileless-like execution method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adding a startup shortcut to the All Users Startup folder.

    Why it's wrong here

    The Startup folder is a well-documented and frequently monitored location. It is considered an entry-level persistence mechanism that is easily detected by antivirus software and endpoint detection and response (EDR) solutions. It is not considered stealthy for a professional penetration test or an advanced threat actor.

  • ✓

    Creating a WMI event subscription for system events.

    Why this is correct

    WMI event subscriptions allow attackers to execute code when specific system conditions are met. Because these subscriptions are stored in the WMI repository rather than standard registry keys, they evade basic persistence checks, making them a highly effective and stealthy method for maintaining long-term access to a Windows system.

  • ✗

    Modifying the existing service binary to include a backdoor.

    Why it's wrong here

    Modifying existing system binaries is highly risky, as it triggers file integrity monitoring (FIM) and is likely to be detected by EDR solutions. Furthermore, it requires administrative privileges that the attacker might not have, making this method both loud and potentially difficult to execute during the escalation phase.

  • ✗

    Running a scheduled task with a visible command prompt window.

    Why it's wrong here

    Scheduled tasks that launch visible windows are immediately obvious to the system user. Stealth is a key component of effective persistence, and any method that interferes with the user experience or is clearly visible is likely to be investigated and removed by the user or security personnel.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.