PT0-002 Attacks and Exploits Practice Question
During a post-exploitation phase, a tester needs to establish persistence on a Windows target. Which THREE methods are commonly used for persistence on Windows?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Registry Run keys
Scheduled tasks, registry Run keys, and WMI subscriptions are common persistence mechanisms. Pass-the-hash is lateral movement, and cron jobs are Linux-specific.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-the-hash
Why it's wrong here
Pass-the-hash is a lateral movement technique that leverages captured NTLM password hashes to authenticate to remote Windows systems without needing the plaintext password. It enables an attacker to move across a network by replaying the hash during an authentication exchange, but it does not create a lasting foothold. Because it only facilitates one-time or session-based authentication, it offers no mechanism to execute code automatically on a recurring basis, making it entirely unsuitable as a persistence technique.
- ✗
Cron jobs
Why it's wrong here
Cron jobs are a Unix/Linux job scheduler utility, not a native Windows component; Windows uses Task Scheduler instead. In a typical Windows post-exploitation scenario, cron would not exist and attempting to use it would likely fail or be ignored. Even on Linux, a cron job could be used for persistence, but in the context of this Windows-focused question, it is the wrong mechanism because it simply does not map to the platform's persistence architecture.
- ✓
Registry Run keys
Why this is correct
Registry Run keys are a classic Windows persistence mechanism where an attacker adds a value to a run key such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Any executable referenced by these keys launches automatically when the designated user logs on, requiring minimal privileges for the HKCU variant and no need for a service or scheduled trigger. This is a straightforward, widely used persistence method that directly survives a reboot and re-authentication of the compromised user account.
- ✓
WMI subscriptions
Why this is correct
WMI (Windows Management Instrumentation) event subscriptions allow persistence by registering an event filter, an event consumer, and a filter-to-consumer binding that executes a script or command when a specified event occurs, such as system startup or a particular time. The subscription is stored in the WMI repository using namespaces like root\subscription, and it can run with SYSTEM privileges via classes like __InstanceCreationEvent and ActiveScriptEventConsumer. This method is highly stealthy because it does not create a file in common startup locations, but it relies on the WMI service (winmgmt) being running continuously.
- ✓
Scheduled tasks
Why this is correct
Scheduled tasks are a legitimate Windows feature that can be abused for persistence by creating a new task triggered at user logon, system startup, or on an idle or time-based event. Attackers use schtasks.exe or the Task Scheduler API to register a task that runs a malicious binary or command with specified privileges, often SYSTEM. Once installed, the task persists across reboots and automatically launches the payload based on its trigger, making it a robust persistence mechanism that is also easy to administer and detect if the target is not carefully monitored.
Go deeper
Related to this question
Learn chapter
Privilege Escalation on Windows
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.