Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing post-exploitation on a compromised Linux server and wants to maintain persistence. Which TWO of the following methods are commonly used for Linux persistence?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adding SSH authorized_keys

Cron jobs and SSH authorized_keys are common persistence techniques. Scheduled tasks are Windows-specific, registry is Windows, WMI is Windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modifying registry Run keys

    Why it's wrong here

    This technique modifies Windows registry keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) to execute a payload automatically at user logon. The registry is a core Windows configuration database, and the required paths and APIs simply do not exist on Linux systems. Thus, attempting to alter registry Run keys on a compromised Linux host is nonsensical and would not achieve persistence.

  • ✗

    Creating scheduled tasks

    Why it's wrong here

    Scheduled Tasks are a component of the Windows Task Scheduler (schtasks.exe), which runs jobs at specified times or on events such as logon or idle. Linux does not use the Task Scheduler; the equivalent functionality is provided by cron or systemd timers. Therefore, creating a 'scheduled task' in this manner is Windows-specific and will not work on a Linux target.

  • ✗

    Creating WMI subscriptions

    Why it's wrong here

    Windows Management Instrumentation (WMI) event subscriptions involve registering a filter, consumer, and binding so that a command executes when a certain event occurs. WMI is a Windows-only management framework; Linux has no WMI service or equivalent interfaces. Consequently, creating WMI subscriptions is ineffective for persistence on a non-Windows system.

  • ✓

    Adding SSH authorized_keys

    Why this is correct

    Appending an attacker-controlled public key to ~/.ssh/authorized_keys on the compromised Linux host enables passwordless SSH authentication for that user at any time. This grants persistent remote access that survives reboots and does not rely on additional commands running at intervals. It is a stealthy and reliable persistence method, especially on servers where SSH is exposed.

  • ✓

    Creating cron jobs

    Why this is correct

    Cron is the native job scheduler on Unix-like systems, allowing commands or scripts to run at scheduled intervals, on reboot, or via @reboot directives. An attacker can add a crontab entry to execute a reverse shell or a persistent script periodically. This is a legitimate and commonly used Linux persistence technique, though it may be slightly more visible in system logs than SSH key-based access.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.