Courseiva

GSEC Malicious Code and Exploit Mitigation Practice Question

A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?

⚠ Common exam trap

The trap here is assuming that any suspicious child process of notepad.exe indicates a specific persistence method like WMI or registry keys, when the scenario explicitly points to a scheduled task.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled task created via schtasks.exe

The malware established persistence by creating a scheduled task that masquerades as a legitimate Microsoft Edge update task. This technique allows the malicious PowerShell script to run at logon or on a schedule. The task name mimics a trusted component to evade detection. The other options are valid persistence methods but do not align with the observed artifact of a scheduled task created by cmd.exe.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scheduled task created via schtasks.exe

    Why this is correct

    The analyst observed that cmd.exe created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from AppData. This is a classic persistence technique using the Windows Task Scheduler, often executed via schtasks.exe or the Task Scheduler COM API. The task masquerades as a legitimate Microsoft Edge update task to avoid suspicion, confirming scheduled task persistence.

  • ✗

    Service creation using sc.exe

    Why it's wrong here

    Creating a Windows service via sc.exe is another persistence technique, but it would result in a new service entry, not a scheduled task. The scenario describes a scheduled task named after a Microsoft Edge update component, which is inconsistent with service creation. No service creation activity is mentioned, so this option is incorrect.

  • ✗

    Registry Run key modification

    Why it's wrong here

    Registry Run keys are a common persistence method, but they would not create a scheduled task. The scenario explicitly states that a scheduled task was created, which is a distinct mechanism. While an attacker could also modify Run keys, the observed artifact is a scheduled task, so this option does not match the evidence.

  • ✗

    Windows Management Instrumentation (WMI) event subscription

    Why it's wrong here

    WMI event subscriptions are a valid persistence mechanism, but the scenario explicitly describes the creation of a scheduled task, not a WMI __EventFilter or __EventConsumer. WMI persistence would not produce a scheduled task named after a legitimate updater. The observed scheduled task points directly to a different technique, making WMI event subscription incorrect for this specific scenario.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.