GSEC Windows Services and MS Cloud Practice Question
A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?
⚠ Common exam trap
Test-takers frequently confuse the Run keys, which are for user logon persistence, with the Services key, which is specifically for Windows service configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has a subkey with values like ImagePath and Start. A malicious service would create a subkey here to ensure it starts automatically. The other locations are used for different persistence mechanisms, such as user logon scripts or are non-existent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Why this is correct
Windows services are configured under HKLM\SYSTEM\CurrentControlSet\Services. Each subkey corresponds to a service and contains values such as ImagePath, Start, and ObjectName. A malicious service would create a subkey here. This is the correct location to examine for service persistence.
- ✗
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
Why it's wrong here
There is no standard registry key named 'Svchost' under that path. Svchost.exe groups services, but its configuration is not stored in a dedicated registry key. Service configurations are stored under the Services key. Therefore, this location is incorrect and likely a distractor.
- ✗
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
The Run key is used for programs that execute at user logon, not for services. Malicious services are not typically configured there. The analyst should look at the Services key instead. The Run key is a common persistence location for user-level malware, but it is not the correct location for service configurations.
- ✗
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
This key is for programs that run at the logon of the current user. It is not used for services, which run under the System account or other service accounts. Malicious services would not be configured here, so this is not the correct location to investigate.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.