Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload contains the path /lib/libprocess.so, which is not a standard library. The responder suspects an attacker is using this for persistence and privilege escalation. Which post-exploitation technique is being employed?

⚠ Common exam trap

Candidates often confuse LD_PRELOAD environment variable hijacking with system-wide preloading via /etc/ld.so.preload; the latter is more persistent and affects all users and processes, not just those with the environment variable set.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic linker preloading via /etc/ld.so.preload

The /etc/ld.so.preload file is used by the dynamic linker to load specified shared libraries before any others for all dynamically linked executables. An attacker can place a malicious library there to intercept function calls, escalate privileges, or maintain persistence. This technique is stealthy because it affects all programs and is not easily detected by process monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cron job persistence

    Why it's wrong here

    Cron jobs are scheduled tasks that run at specified intervals. They are a common persistence method, but they do not involve shared libraries. The presence of a non-standard library in /etc/ld.so.preload indicates a different technique: dynamic linker preloading. Cron jobs would be found in crontab files or /etc/cron.* directories, not in ld.so.preload.

  • ✗

    Kernel module rootkit insertion

    Why it's wrong here

    Kernel module rootkits involve loading malicious code into the kernel, often via insmod or modprobe. This requires root privileges and leaves traces in kernel memory. The scenario describes a user-space shared library preloading mechanism, not a kernel module. The file /etc/ld.so.preload is used by the dynamic linker, not the kernel, so this technique is different.

  • ✗

    LD_PRELOAD environment variable hijacking

    Why it's wrong here

    LD_PRELOAD is an environment variable that allows loading shared libraries before others. However, it only affects processes that inherit the environment variable. By modifying /etc/ld.so.preload, the attacker ensures the library is loaded for all dynamically linked executables system-wide, regardless of environment. Thus, this is a more persistent and global technique than LD_PRELOAD alone.

  • ✓

    Dynamic linker preloading via /etc/ld.so.preload

    Why this is correct

    The /etc/ld.so.preload file specifies shared libraries to be loaded by the dynamic linker before any others for all executables. Attackers can place a malicious library there to intercept function calls, log keystrokes, or escalate privileges. This is a stealthy persistence mechanism because it affects all dynamically linked programs and is not obvious in process lists.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.