An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)
User crontab files are stored under /var/spool/cron/crontabs/, with one file per user, making it a standard location attackers modify to schedule recurring commands. This satisfies the cron persistence requirement, unlike directories holding system binaries or logs.
Why this answer
Option A (/var/spool/cron/crontabs/) is correct because this is the directory where per-user crontab files are stored on Debian/Ubuntu-style systems, and attackers commonly drop a crontab entry here to run a payload under a specific user account at scheduled intervals. Option C (/etc/crontab) is correct because it is the system-wide crontab file that supports the extra user field and is a frequent target for persistence, since a malicious line added here executes with the specified user's privileges on a recurring schedule. Option B (/etc/init.d/) is not cron-based; it holds SysV init scripts for service startup, not scheduled jobs.
Option D (/var/log/cron) is a log file recording cron activity, useful for detection but not a persistence location. Option E (/etc/systemd/system/) is for systemd unit files, a separate persistence mechanism from cron.
Exam trap
200-201 often tests distinguishing persistence mechanisms by category — candidates confuse cron locations with init/systemd service directories, picking /etc/init.d/ or /etc/systemd/system/ when the question specifically asks about cron.