GPEN Domain Escalation and Persistence Practice Question
Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?
⚠ Common exam trap
Candidates often suggest common techniques like Run keys or startup folders, overlooking that these are heavily monitored. WMI is chosen specifically for its ability to operate stealthily without registry modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating a WMI event subscription for system events.
Persistence is often detected via common registry keys like Run or RunOnce. Using Windows Management Instrumentation (WMI) event subscriptions allows for persistence that is harder to detect. By creating an EventFilter and EventConsumer, an attacker can trigger a malicious script based on system events, such as a specific time or system uptime, bypassing traditional registry-based forensic analysis and providing a robust, fileless-like execution method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adding a startup shortcut to the All Users Startup folder.
Why it's wrong here
The Startup folder is a well-documented and frequently monitored location. It is considered an entry-level persistence mechanism that is easily detected by antivirus software and endpoint detection and response (EDR) solutions. It is not considered stealthy for a professional penetration test or an advanced threat actor.
- ✓
Creating a WMI event subscription for system events.
Why this is correct
WMI event subscriptions allow attackers to execute code when specific system conditions are met. Because these subscriptions are stored in the WMI repository rather than standard registry keys, they evade basic persistence checks, making them a highly effective and stealthy method for maintaining long-term access to a Windows system.
- ✗
Modifying the existing service binary to include a backdoor.
Why it's wrong here
Modifying existing system binaries is highly risky, as it triggers file integrity monitoring (FIM) and is likely to be detected by EDR solutions. Furthermore, it requires administrative privileges that the attacker might not have, making this method both loud and potentially difficult to execute during the escalation phase.
- ✗
Running a scheduled task with a visible command prompt window.
Why it's wrong here
Scheduled tasks that launch visible windows are immediately obvious to the system user. Stealth is a key component of effective persistence, and any method that interferes with the user experience or is clearly visible is likely to be investigated and removed by the user or security personnel.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.