Courseiva

GSEC Windows Automation and Auditing Practice Question

A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?

⚠ Common exam trap

The trap here is assuming that 'not running' means only 'Stopped' or using -or instead of -and, which broadens the results incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -ne 'Running'}

To find automatic services that are not running, you must filter by StartType equal to 'Automatic' and Status not equal to 'Running'. The correct command uses Where-Object with -and and -ne to capture all non-running states. This ensures you don't miss services that are paused or in transition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -ne 'Running'}

    Why this is correct

    This command filters services where the StartType is 'Automatic' and the Status is not 'Running'. It directly returns the list of automatic services that are stopped or in another non-running state. The Where-Object cmdlet evaluates each service object, and the condition uses -and to combine both criteria. This is the most straightforward and accurate way to achieve the goal.

  • ✗

    Get-Service -StartType Automatic | Where-Object {$_.Status -eq 'Stopped'}

    Why it's wrong here

    The Get-Service cmdlet does not have a -StartType parameter. While you can filter by -Name or -DisplayName, StartType is not a valid parameter. This command would produce an error. Even if it worked, it only checks for 'Stopped' status, missing services that are in 'Paused' or 'StartPending' states. The correct approach uses Get-Service without that parameter and then filters with Where-Object.

  • ✗

    Get-Service | Where-Object {$_.StartType -eq 'Automatic' -or $_.Status -eq 'Stopped'}

    Why it's wrong here

    Using -or would return all automatic services regardless of status, plus all stopped services regardless of start type. This includes many services that are not automatic or not stopped, creating a large and inaccurate list. The goal is to find automatic services that are not running, so the condition must use -and, not -or. This command would not efficiently identify the desired services.

  • ✗

    Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -eq 'Stopped'}

    Why it's wrong here

    This command filters for automatic services that are specifically 'Stopped'. While this might cover most cases, it excludes services that are in 'Paused', 'StartPending', or 'StopPending' states. The question asks for services not running, which includes any status other than 'Running'. Therefore, using -ne 'Running' is more accurate. This option is close but not fully correct.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.