GSEC Malicious Code and Exploit Mitigation Practice Question
A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?
⚠ Common exam trap
The trap here is assuming that any suspicious child process of notepad.exe indicates a specific persistence method like WMI or registry keys, when the scenario explicitly points to a scheduled task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scheduled task created via schtasks.exe
The malware established persistence by creating a scheduled task that masquerades as a legitimate Microsoft Edge update task. This technique allows the malicious PowerShell script to run at logon or on a schedule. The task name mimics a trusted component to evade detection. The other options are valid persistence methods but do not align with the observed artifact of a scheduled task created by cmd.exe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scheduled task created via schtasks.exe
Why this is correct
The analyst observed that cmd.exe created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from AppData. This is a classic persistence technique using the Windows Task Scheduler, often executed via schtasks.exe or the Task Scheduler COM API. The task masquerades as a legitimate Microsoft Edge update task to avoid suspicion, confirming scheduled task persistence.
- ✗
Service creation using sc.exe
Why it's wrong here
Creating a Windows service via sc.exe is another persistence technique, but it would result in a new service entry, not a scheduled task. The scenario describes a scheduled task named after a Microsoft Edge update component, which is inconsistent with service creation. No service creation activity is mentioned, so this option is incorrect.
- ✗
Registry Run key modification
Why it's wrong here
Registry Run keys are a common persistence method, but they would not create a scheduled task. The scenario explicitly states that a scheduled task was created, which is a distinct mechanism. While an attacker could also modify Run keys, the observed artifact is a scheduled task, so this option does not match the evidence.
- ✗
Windows Management Instrumentation (WMI) event subscription
Why it's wrong here
WMI event subscriptions are a valid persistence mechanism, but the scenario explicitly describes the creation of a scheduled task, not a WMI __EventFilter or __EventConsumer. WMI persistence would not produce a scheduled task named after a legitimate updater. The observed scheduled task points directly to a different technique, making WMI event subscription incorrect for this specific scenario.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.