CHFI OS and Network Forensics Practice Question
During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?
⚠ Common exam trap
EC-CHFI often tests the distinction between cron jobs and systemd timers or init scripts, and the trap here is that candidates may confuse the /etc/cron.d/ directory with init scripts or systemd unit files, not realizing that cron is a separate scheduler with its own file format and location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cron job
The cron daemon reads job definitions from files in /etc/cron.d/ and executes them according to the schedule specified. Finding a file named 'malware' in /etc/cron.d/ that runs every 5 minutes as root directly indicates a cron job persistence mechanism, as this is the standard location for system-wide cron entries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bash history
Why it's wrong here
Bash history is incorrect because it is a passive log file, typically ~/.bash_history, that records interactive shell commands entered by users. It does not possess any scheduling or self-executing capability, so although an investigator might find a suspicious command recorded there, the history itself never triggers or runs anything. Its forensic value is purely artifact-based, showing past actions, not an active execution mechanism.
- ✗
Systemd service
Why it's wrong here
Systemd service is incorrect because unit files under /etc/systemd/system/ define long-running daemons or one-shot processes that systemd supervises and launches at boot or on demand. They are event- or boot-driven, not time-scheduled like cron jobs, and the /etc/cron.d/ directory is specifically reserved for cron tab definitions, not systemd units. A malicious systemd service is a persistence technique, but it would not be identified as a cron job.
- ✓
Cron job
Why this is correct
Cron job is correct because /etc/cron.d/ contains cron schedule files that the cron daemon parses and executes at predefined time intervals using the standard 'minute hour day month weekday' syntax. These jobs run as the specified user and can be set to execute arbitrary commands, making them a common mechanism attackers use for scheduled persistence. The file's presence in /etc/cron.d/ with a valid time specification directly indicates a cron job rather than any other startup or logging mechanism.
- ✗
Init script
Why it's wrong here
Init script is incorrect because SysV init scripts reside in /etc/init.d/ and are executed by the init process during system boot or runlevel changes, not at periodic time intervals. They are boot-time automation, triggered by runlevel traversal, and are not parsed by cron; a schedule specification is meaningless to them. In a forensic context, finding a script in /etc/init.d/ suggests boot persistence, but it does not constitute a scheduled cron job.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.