20+ practice questions focused on Domain Escalation and Persistence — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Domain Escalation and Persistence PracticeRefer to the exhibit. As a penetration tester, you discover this registry key. What is the primary security implication of this finding regarding persistence?
Explanation: The registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism. Since it resides in HKLM, it runs for every user that logs into the system. Identifying this key allows a tester to confirm persistence on the target. If the current user has write access to the binary location, they can replace the legitimate executable with a malicious one, effectively escalating privileges upon the next system startup.
Refer to the exhibit. What is the security concern regarding this service configuration?
Explanation: The service is configured as AUTO_START and runs as LocalSystem. If the binary path were replaced or if the service could be hijacked via DLL sideloading, an attacker would gain execution with SYSTEM privileges automatically upon boot. While the path points to a legitimate system binary, the configuration details suggest that any vulnerability in the associated service logic could lead to complete system compromise via persistence.
During a penetration test on an Active Directory environment, you have compromised a workstation and want to maintain persistence across reboots without modifying the registry or creating scheduled tasks. You have local administrator rights. Which method is most appropriate?
Explanation: WMI event subscriptions are stored in the WMI repository and can trigger on system startup without modifying the registry or creating scheduled tasks. This makes them a stealthy persistence mechanism that meets the scenario's constraints. They are often missed by rudimentary persistence checks that focus on Run keys or Task Scheduler, and they can execute arbitrary code with the privileges of the WMI service.
A penetration tester has gained Domain Admin access and wants to establish persistence on a Windows domain. The tester must ensure the persistence survives a reboot of the domain controller and remains undetected by standard security audits. Which TWO of the following techniques best meet these requirements? (Choose two.)
Explanation: A Golden Ticket and a Skeleton Key both provide stealthy domain persistence. The Golden Ticket is forged from the krbtgt hash and remains valid until the krbtgt password is reset twice, surviving reboots without on-disk artifacts. A Skeleton Key patches LSASS to accept a master password, allowing access without changing accounts or ACLs. Both avoid the obvious indicators of new accounts, ACL changes, or scheduled tasks.
During a penetration test, you gain access to a Linux server and want to establish persistence by creating a new user account with root privileges. Which of the following methods is most likely to succeed and remain stealthy?
Explanation: Creating a user with UID 0 is a stealthy persistence method because it grants root privileges without altering existing accounts or sudo configurations. It is less likely to be detected unless administrators specifically look for duplicate UID 0 entries.
+15 more Domain Escalation and Persistence questions available
Practice all Domain Escalation and Persistence questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Domain Escalation and Persistence. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Domain Escalation and Persistence questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Domain Escalation and Persistence is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Domain Escalation and Persistence questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Domain Escalation and Persistence is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Domain Escalation and Persistence practice session with instant scoring and detailed explanations.
Start Domain Escalation and Persistence Practice →