GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload contains the path /lib/libprocess.so, which is not a standard library. The responder suspects an attacker is using this for persistence and privilege escalation. Which post-exploitation technique is being employed?
⚠ Common exam trap
Candidates often confuse LD_PRELOAD environment variable hijacking with system-wide preloading via /etc/ld.so.preload; the latter is more persistent and affects all users and processes, not just those with the environment variable set.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic linker preloading via /etc/ld.so.preload
The /etc/ld.so.preload file is used by the dynamic linker to load specified shared libraries before any others for all dynamically linked executables. An attacker can place a malicious library there to intercept function calls, escalate privileges, or maintain persistence. This technique is stealthy because it affects all programs and is not easily detected by process monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cron job persistence
Why it's wrong here
Cron jobs are scheduled tasks that run at specified intervals. They are a common persistence method, but they do not involve shared libraries. The presence of a non-standard library in /etc/ld.so.preload indicates a different technique: dynamic linker preloading. Cron jobs would be found in crontab files or /etc/cron.* directories, not in ld.so.preload.
- ✗
Kernel module rootkit insertion
Why it's wrong here
Kernel module rootkits involve loading malicious code into the kernel, often via insmod or modprobe. This requires root privileges and leaves traces in kernel memory. The scenario describes a user-space shared library preloading mechanism, not a kernel module. The file /etc/ld.so.preload is used by the dynamic linker, not the kernel, so this technique is different.
- ✗
LD_PRELOAD environment variable hijacking
Why it's wrong here
LD_PRELOAD is an environment variable that allows loading shared libraries before others. However, it only affects processes that inherit the environment variable. By modifying /etc/ld.so.preload, the attacker ensures the library is loaded for all dynamically linked executables system-wide, regardless of environment. Thus, this is a more persistent and global technique than LD_PRELOAD alone.
- ✓
Dynamic linker preloading via /etc/ld.so.preload
Why this is correct
The /etc/ld.so.preload file specifies shared libraries to be loaded by the dynamic linker before any others for all executables. Attackers can place a malicious library there to intercept function calls, log keystrokes, or escalate privileges. This is a stealthy persistence mechanism because it affects all dynamically linked programs and is not obvious in process lists.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.