Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?

⚠ Common exam trap

EC-CHFI often tests the distinction between cron jobs and systemd timers or init scripts, and the trap here is that candidates may confuse the /etc/cron.d/ directory with init scripts or systemd unit files, not realizing that cron is a separate scheduler with its own file format and location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cron job

The cron daemon reads job definitions from files in /etc/cron.d/ and executes them according to the schedule specified. Finding a file named 'malware' in /etc/cron.d/ that runs every 5 minutes as root directly indicates a cron job persistence mechanism, as this is the standard location for system-wide cron entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bash history

    Why it's wrong here

    Bash history is incorrect because it is a passive log file, typically ~/.bash_history, that records interactive shell commands entered by users. It does not possess any scheduling or self-executing capability, so although an investigator might find a suspicious command recorded there, the history itself never triggers or runs anything. Its forensic value is purely artifact-based, showing past actions, not an active execution mechanism.

  • ✗

    Systemd service

    Why it's wrong here

    Systemd service is incorrect because unit files under /etc/systemd/system/ define long-running daemons or one-shot processes that systemd supervises and launches at boot or on demand. They are event- or boot-driven, not time-scheduled like cron jobs, and the /etc/cron.d/ directory is specifically reserved for cron tab definitions, not systemd units. A malicious systemd service is a persistence technique, but it would not be identified as a cron job.

  • ✓

    Cron job

    Why this is correct

    Cron job is correct because /etc/cron.d/ contains cron schedule files that the cron daemon parses and executes at predefined time intervals using the standard 'minute hour day month weekday' syntax. These jobs run as the specified user and can be set to execute arbitrary commands, making them a common mechanism attackers use for scheduled persistence. The file's presence in /etc/cron.d/ with a valid time specification directly indicates a cron job rather than any other startup or logging mechanism.

  • ✗

    Init script

    Why it's wrong here

    Init script is incorrect because SysV init scripts reside in /etc/init.d/ and are executed by the init process during system boot or runlevel changes, not at periodic time intervals. They are boot-time automation, triggered by runlevel traversal, and are not parsed by cron; a schedule specification is meaningless to them. In a forensic context, finding a script in /etc/init.d/ suggests boot persistence, but it does not constitute a scheduled cron job.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.