Courseiva

GPEN Domain Escalation and Persistence Practice Question

Which TWO of the following are common indicators that a Windows system has been compromised with persistence?

⚠ Common exam trap

Candidates often look only for obvious malware files. They fail to recognize that legitimate-looking services or startup entries running as SYSTEM are the most reliable indicators of persistent compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Presence of unknown services running as SYSTEM.

Indicators of persistence in Windows include unusual entries in startup folders, unrecognized services set to auto-start, and suspicious registry keys. Monitoring these areas is standard procedure for incident response and threat hunting. Detecting these markers early allows defenders to disrupt the attacker's ability to maintain access, effectively ending the persistence phase and forcing the attacker to re-establish a foothold, which increases the likelihood of detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Presence of unknown services running as SYSTEM.

    Why this is correct

    Malware often installs itself as a service to ensure it runs with high privileges upon system startup. An unrecognized service running as SYSTEM is a major red flag that warrants immediate investigation, as it is a common method for achieving both persistence and privilege escalation on Windows servers.

  • ✗

    Increased usage of the CPU by the system kernel.

    Why it's wrong here

    High kernel CPU usage is often related to driver issues, hardware problems, or system-level bottlenecks. While some malware might cause performance issues, it is not a primary indicator of persistence. More reliable indicators are configuration changes that ensure code execution upon reboot, rather than general performance-based telemetry data.

  • ✓

    Unexpected files in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder.

    Why this is correct

    The Startup folder is a classic location for persistent execution. If a user finds an unfamiliar executable or shortcut in this location, it is a strong indicator that an attacker has established persistence. This folder is monitored frequently by security teams to detect unauthorized software that runs at login.

  • ✗

    Changes to the system's desktop wallpaper.

    Why it's wrong here

    Changing the wallpaper is a trivial, non-persistent action that is often performed by pranksters. It does not provide any mechanism for maintaining access across reboots and is not considered a reliable indicator of a serious security compromise or persistent threat actor presence within a target environment.

  • ✗

    A high number of failed login attempts in the event log.

    Why it's wrong here

    Failed login attempts are indicative of a brute-force or password-spraying attack, not persistence. Persistence is about maintaining access once you are already on the system. While brute force is part of the initial access phase, it is not a direct marker of successfully established persistence on the host.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.