PT0-002 Attacks and Exploits Practice Question
A tester is performing a post-exploitation phase on a compromised Linux server and wants to establish persistence. Which THREE of the following methods are commonly used for Linux persistence? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adding an SSH public key to ~/.ssh/authorized_keys
Common Linux persistence methods include adding cron jobs (crontab), creating a systemd service that starts on boot, and adding SSH authorized keys for backdoor access. Scheduled tasks are Windows-specific; Registry Run keys are also Windows-only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adding a registry Run key
Why it's wrong here
The Windows Registry is a hierarchical database that stores low-level settings for the operating system and applications. A Run key in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run instructs Windows to launch a specified program at user logon. Because the compromised target is a Linux host, there is no Registry hive or Run key mechanism, making this option invalid and platform-inappropriate for persistence.
- ✓
Adding an SSH public key to ~/.ssh/authorized_keys
Why this is correct
Appending the attacker's public key to ~/.ssh/authorized_keys enables passwordless key-based authentication for the targeted user account. This grants persistent SSH access without needing to re-establish a foothold through a vulnerability, and it remains effective across reboots and user sessions. The private key stays with the attacker, allowing them to authenticate at any time as long as the SSH service is exposed and the user account remains valid.
- ✓
Creating a systemd service to start on boot
Why this is correct
Creating a systemd service unit file, such as /etc/systemd/system/backdoor.service, and enabling it with systemctl enable ensures the service is started automatically on boot. The service can be configured with Type=simple and ExecStart to launch a reverse shell or a payload with the desired privileges. Systemd is the default init system on most modern Linux distributions, so this provides reliable persistent execution that does not depend on a user logging in.
- ✗
Creating a scheduled task using schtasks
Why it's wrong here
The schtasks utility is a Windows command-line tool used to schedule tasks via the Task Scheduler component. It requires the Windows Task Scheduler service and sees no equivalent on a Linux system, which uses cron or systemd timers instead. Running schtasks against a compromised Linux target would fail because the binary and underlying scheduling infrastructure do not exist.
- ✓
Adding a cron job to execute a reverse shell periodically
Why this is correct
Adding an entry to the user's crontab, for example with a * * * * * schedule, causes the cron daemon to execute a designated command every minute. This allows the tester to launch a reverse shell or re-establish a callback at regular intervals, making rapid recovery after a connection drops. The technique is effective for persistence but generates periodic process activity that system monitoring tools may flag.
Go deeper
Related to this question
Learn chapter
Post-Exploitation File Transfer Techniques
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.