Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

During a post-exploitation phase, a tester needs to establish persistence on a Windows target. Which THREE methods are commonly used for persistence on Windows?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry Run keys

Scheduled tasks, registry Run keys, and WMI subscriptions are common persistence mechanisms. Pass-the-hash is lateral movement, and cron jobs are Linux-specific.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pass-the-hash

    Why it's wrong here

    Pass-the-hash is a lateral movement technique that leverages captured NTLM password hashes to authenticate to remote Windows systems without needing the plaintext password. It enables an attacker to move across a network by replaying the hash during an authentication exchange, but it does not create a lasting foothold. Because it only facilitates one-time or session-based authentication, it offers no mechanism to execute code automatically on a recurring basis, making it entirely unsuitable as a persistence technique.

  • ✗

    Cron jobs

    Why it's wrong here

    Cron jobs are a Unix/Linux job scheduler utility, not a native Windows component; Windows uses Task Scheduler instead. In a typical Windows post-exploitation scenario, cron would not exist and attempting to use it would likely fail or be ignored. Even on Linux, a cron job could be used for persistence, but in the context of this Windows-focused question, it is the wrong mechanism because it simply does not map to the platform's persistence architecture.

  • ✓

    Registry Run keys

    Why this is correct

    Registry Run keys are a classic Windows persistence mechanism where an attacker adds a value to a run key such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Any executable referenced by these keys launches automatically when the designated user logs on, requiring minimal privileges for the HKCU variant and no need for a service or scheduled trigger. This is a straightforward, widely used persistence method that directly survives a reboot and re-authentication of the compromised user account.

  • ✓

    WMI subscriptions

    Why this is correct

    WMI (Windows Management Instrumentation) event subscriptions allow persistence by registering an event filter, an event consumer, and a filter-to-consumer binding that executes a script or command when a specified event occurs, such as system startup or a particular time. The subscription is stored in the WMI repository using namespaces like root\subscription, and it can run with SYSTEM privileges via classes like __InstanceCreationEvent and ActiveScriptEventConsumer. This method is highly stealthy because it does not create a file in common startup locations, but it relies on the WMI service (winmgmt) being running continuously.

  • ✓

    Scheduled tasks

    Why this is correct

    Scheduled tasks are a legitimate Windows feature that can be abused for persistence by creating a new task triggered at user logon, system startup, or on an idle or time-based event. Attackers use schtasks.exe or the Task Scheduler API to register a task that runs a malicious binary or command with specified privileges, often SYSTEM. Once installed, the task persists across reboots and automatically launches the payload based on its trigger, making it a robust persistence mechanism that is also easy to administer and detect if the target is not carefully monitored.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.