GSEC Malicious Code and Exploit Mitigation Practice Question
A security analyst is reviewing an incident where a user's browser was exploited by a drive-by download. The analyst wants to confirm whether the exploit achieved code execution and established persistence. Which artifact should the analyst examine first to determine if a new service was created for persistence on the Windows host?
⚠ Common exam trap
Watch out — candidates often confuse process creation telemetry with service installation telemetry; event ID 4688 shows that a process ran, while event ID 7045 proves a service was actually installed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The System event log for event ID 7045 Service Control Manager entries.
The System event log entry with ID 7045 is generated by the Service Control Manager whenever a new service is installed on Windows. It captures the service name, binary path, start type, and account, which lets the analyst confirm both installation and the persistence mechanism. Unlike process creation auditing, 7045 is enabled by default and directly answers whether a service was created, making it the correct first artifact to examine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Application event log for Windows Error Reporting crash entries.
Why it's wrong here
Windows Error Reporting entries in the Application log document application crashes and may show that the browser or a plugin crashed during exploitation, but they do not record service creation. A crash is not proof of successful code execution or persistence, and many exploits fail silently without generating WER reports. This artifact is therefore not the right place to confirm whether a new service was installed.
- ✗
The browser's cache folder for recently downloaded JavaScript files.
Why it's wrong here
The browser cache can reveal the lure or exploit script that triggered the drive-by download, but it does not record whether a Windows service was created. Cache files are stored per-user and are often overwritten quickly, and they cannot show service installation events. To confirm persistence via a new service, the analyst needs the system event log that records service creation, not the browser cache.
- ✗
The Windows Security event log for event ID 4688 process creation.
Why it's wrong here
Event ID 4688 records process creation and can show that sc.exe or services.exe was invoked, but it does not by itself confirm that a new service was successfully installed. Process creation auditing must also be enabled in advance. While useful for tracing the exploit chain, 4688 is a process-level artifact and does not directly enumerate service installation, so it is not the first artifact for confirming service-based persistence.
- ✓
The System event log for event ID 7045 Service Control Manager entries.
Why this is correct
Event ID 7045 in the System log is written by the Service Control Manager when a new service is installed, and it records the service name, image path, service type, and start type. This directly answers whether a new service was created for persistence. It is generated by default on modern Windows systems, requires no pre-enabled auditing, and provides the exact evidence needed to confirm service installation after a drive-by exploit.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.