Courseiva

GSEC Windows Services and MS Cloud Practice Question

A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?

⚠ Common exam trap

Test-takers frequently confuse the Run keys, which are for user logon persistence, with the Services key, which is specifically for Windows service configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has a subkey with values like ImagePath and Start. A malicious service would create a subkey here to ensure it starts automatically. The other locations are used for different persistence mechanisms, such as user logon scripts or are non-existent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

    Why this is correct

    Windows services are configured under HKLM\SYSTEM\CurrentControlSet\Services. Each subkey corresponds to a service and contains values such as ImagePath, Start, and ObjectName. A malicious service would create a subkey here. This is the correct location to examine for service persistence.

  • ✗

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost

    Why it's wrong here

    There is no standard registry key named 'Svchost' under that path. Svchost.exe groups services, but its configuration is not stored in a dedicated registry key. Service configurations are stored under the Services key. Therefore, this location is incorrect and likely a distractor.

  • ✗

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    The Run key is used for programs that execute at user logon, not for services. Malicious services are not typically configured there. The analyst should look at the Services key instead. The Run key is a common persistence location for user-level malware, but it is not the correct location for service configurations.

  • ✗

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    This key is for programs that run at the logon of the current user. It is not used for services, which run under the System account or other service accounts. Malicious services would not be configured here, so this is not the correct location to investigate.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.