GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 139


Which persistence mechanism will evade detection by Sysinternals AutoRuns?

Show Answer
Correct Answer: BD

The persistence mechanism that is most likely to evade detection by Sysinternals AutoRuns is WMI event subscription. AutoRuns is designed to detect various autostarting locations including scheduled tasks, user accounts, and new services, which makes these methods more easily detectable. WMI (Windows Management Instrumentation) event subscriptions can be used to achieve persistence in a more stealthy manner as they are less likely to be flagged by AutoRuns.

Discussion

1 comment
Sign in to comment
Vikt0rOption: D
Dec 7, 2023

D WMI Options A (Configuring scheduled tasks), B (Adding user accounts), and C (New service creation) are more likely to be detected by Sysinternals AutoRuns as it is designed to highlight entries associated with scheduled tasks, user accounts, and services.