Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic examiner is analyzing a compromised Linux server and notices that /etc/cron.daily contains a script named 'sysupdate.sh' that runs a base64-encoded command. Which persistence mechanism is being used?

⚠ Common exam trap

A common mix-up: candidates confuse cron directories with other persistence mechanisms like systemd timers or SSH backdoors, but the specific path /etc/cron.daily directly points to a cron-based daily job.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cron job for daily execution

The presence of a script named 'sysupdate.sh' inside /etc/cron.daily indicates that the system's cron daemon is configured to execute this script once per day. Cron jobs are a standard Linux persistence mechanism, and placing a script in /etc/cron.daily ensures it runs automatically on a daily schedule, making option B correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LD_PRELOAD library injection

    Why it's wrong here

    LD_PRELOAD is an environment variable that forces the dynamic linker to load a specified shared object before any others, enabling function hooks and process-level code injection. However, it does not self-schedule or create any entries in cron directories like /etc/cron.daily, and persistence via LD_PRELOAD usually requires a global configuration such as /etc/ld.so.preload or a shell profile, not a cron script. The presence of a file in /etc/cron.daily strongly indicates a scheduled job, not runtime linker injection.

  • ✓

    Cron job for daily execution

    Why this is correct

    A script located in /etc/cron.daily is a clear indicator of a cron-based persistence mechanism, since this directory is executed daily by cron (or anacron) on most Linux distributions. The contents of the script are run with the privileges of the user who owns it, often root, making it a powerful backdoor for maintaining access. Forensic examiners should inspect the script for malicious commands, check its permissions, and correlate the file creation timestamp with the initial compromise window.

  • ✗

    Systemd service

    Why it's wrong here

    Systemd services are defined by unit files with a .service extension stored in /etc/systemd/system/ or /lib/systemd/system/ directories, not in /etc/cron.daily. A systemd unit would be enabled and started via systemctl, and its execution model is event-driven or triggered by dependencies, not a fixed daily schedule. Finding an executable in the cron.daily directory points directly to cron rather than systemd, so this option does not match the evidence in the question.

  • ✗

    SSH authorized_keys backdoor

    Why it's wrong here

    An SSH authorized_keys backdoor involves appending an attacker's public key to a target user's ~/.ssh/authorized_keys file, enabling passwordless SSH login. This persistence method is entirely unrelated to scheduled execution and would not place any file into the system-wide /etc/cron.daily directory. The presence of a script in that directory indicates a cron job, not an SSH backdoor, which would instead be found in a user's home directory and typically grants remote access rather than executing commands on a schedule.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.