CHFI OS and Network Forensics Practice Question
An incident responder examines a Linux server and finds a suspicious cron job that runs every minute and executes a script located in /tmp. Which persistence technique does this represent?
⚠ Common exam trap
This question tests the distinction between user-space persistence mechanisms (like cron) and kernel-level or network-accessible backdoors. Candidates may confuse cron jobs with rootkits or web shells due to overlapping goals of maintaining access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cron-based persistence
Cron is a Linux job scheduler that executes tasks at specified intervals. A cron job running every minute from /tmp indicates an attacker has added a persistent scheduled task to maintain access, which is a classic example of cron-based persistence. This technique leverages the cron daemon (crond) to re-execute malicious code automatically, ensuring the attacker's foothold survives reboots.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kernel rootkit
Why it's wrong here
A kernel rootkit operates at ring 0 by hooking system calls or modifying kernel data structures to hide files, processes, and network connections. While it can provide stealthy persistence, it does not rely on cron, and its artifacts would be found in loaded modules, /dev/kmem, or VFS hooks rather than in crontab entries.
- ✗
Web shell
Why it's wrong here
A web shell is a script deployed in a web-accessible directory (e.g., /var/www/html) and triggered on demand via HTTP GET/POST requests to the web server. It gives interactive remote control only while requested, and its persistence depends on the file remaining in the webroot, not on a cron schedule; finding a suspicious cron entry points to scheduled execution, not web-based access.
- ✗
SSH key backdoor
Why it's wrong here
An SSH key backdoor adds a public key to ~/.ssh/authorized_keys or root's authorized_keys, allowing the attacker to authenticate and gain a shell whenever they initiate an SSH connection. This grants persistent remote access but is event-driven and interactive, with no built-in mechanism to run commands on a fixed schedule; cron, by contrast, executes jobs automatically at specified intervals without requiring an inbound connection.
- ✓
Cron-based persistence
Why this is correct
Cron-based persistence occurs when an attacker adds a job to a user's crontab, /etc/cron.d/, or an /etc/cron.* directory so that the system executes a reverse shell, beacon, or re-implant command at regular intervals. The job runs with the crontab owner's privileges, survives reboots, and can be hidden with output redirection; a finding of a suspicious timer entry is strong evidence of this persistence technique.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.