You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.
Start practicing
Domain Escalation and Persistence — choose a session length
Free · No account required
Domain overview
This domain covers post-exploitation tradecraft on Windows/Active Directory: privilege escalation to Domain Admin, credential abuse (Kerberos, DCSync, LSASS), and durable persistence. GPEN tests whether you can select methods that survive reboots and password resets, and recognize why artifacts like backdoor accounts, Golden Tickets, and Skeleton Keys are dangerous if left behind.
Exam objectives
Golden Ticket and KRBTGT hash abuse for domain-wide Kerberos persistence
DCSync replication rights abuse to extract domain credential hashes
Scheduled tasks, services, and WMI event subscriptions for reboot-surviving persistence
Skeleton Key and AdminSDHolder for stealthy Domain Admin persistence
Confusing Golden Ticket with Silver Ticket: Golden uses KRBTGT and forges TGTs; Silver uses a service account hash and forges service tickets.
Assuming a Golden Ticket dies with a Domain Admin password reset; only KRBTGT resets (twice) invalidate it.
Leaving backdoor accounts, Skeleton Key, or DSRM changes in place after the engagement, creating real risk and failing cleanup.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
2Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?
3When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?
4Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?
5Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?
6Which THREE of the following are valid techniques for privilege escalation on a Linux system?
7Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?
8What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?
9Which TWO of the following are common indicators that a Windows system has been compromised with persistence?
10During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?
11Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?
12A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?
13You have obtained domain administrator credentials during a penetration test. To maintain stealthy persistence on a Windows domain controller, you decide to abuse Kerberos. Which method allows you to authenticate as any user without knowing their password, and is a known persistence technique?
14During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?
15You have obtained Domain Admin credentials during an internal penetration test. To ensure continued access even if the compromised user's password is changed, you decide to create a Golden Ticket. Which artifact is required to forge a Golden Ticket?
16During a penetration test on a Linux system, you have gained root access and want to ensure that your backdoor survives system reboots. Which of the following methods is the most reliable and commonly used for this purpose?
You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.
The Courseiva GPEN question bank contains 16 questions in the Domain Escalation and Persistence domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Domain Escalation and Persistence domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included