GSEC Windows Automation and Auditing Practice Question
Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?
⚠ Common exam trap
Candidates often select commands related to Active Directory or system-wide auditing rather than host-specific local commands. They fail to distinguish between domain-level management and local server-level forensic auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Get-LocalGroupMember -Group Administrators
Effective auditing requires querying local identity stores and task schedules. 'Get-LocalGroupMember' provides a snapshot of accounts with elevated or specific access, while 'Get-ScheduledTask' identifies persistent malicious mechanisms. Understanding these commands is critical for GSEC professionals to perform rapid host-based forensics, as these two areas are frequent targets for persistence and lateral movement by attackers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Get-LocalGroupMember -Group Administrators
Why this is correct
This cmdlet allows an auditor to list all members of the local Administrators group. Monitoring this group is vital, as attackers often add malicious accounts or elevated service accounts to maintain control over the compromised host during the post-exploitation phase.
- ✓
Get-ScheduledTask
Why this is correct
This command retrieves all scheduled tasks on the system. Attackers frequently use tasks to achieve persistence, executing malicious code at specific intervals or upon system startup, making this a high-priority area for auditing during a security incident response.
- ✗
Get-Process -IncludeUserName
Why it's wrong here
While this command identifies running processes and their owners, it does not reveal the configuration of local groups or persistence mechanisms. It is useful for identifying rogue binaries but falls short of the specific requirement to audit groups and tasks.
- ✗
Get-Service | Where-Object {$_.Status -eq 'Running'}
Why it's wrong here
This command audits running services, which is useful for identifying unexpected background activity. However, it does not provide information about user account membership or persistence via tasks, which are the primary focus of the requested audit requirements.
- ✗
Get-WinEvent -LogName Security
Why it's wrong here
This command accesses the security event log. While useful for finding historical data, it does not directly query the static configuration of group memberships or scheduled tasks, which are better served by the specific cmdlets designed for system management and configuration auditing.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.