Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

An incident responder is reviewing a compromised Linux host and notices that the attacker modified the /etc/ld.so.preload file to include a path to a shared object file. Shortly after, the responder observes that common commands like 'ls' and 'ps' are returning incomplete or manipulated output. Which post-exploitation technique has the attacker most likely employed?

⚠ Common exam trap

The trap here is assuming any rootkit requires kernel module loading, when userland rootkits using LD_PRELOAD are simpler to deploy and leave different, file-based artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Userland rootkit using LD_PRELOAD to hook library calls

The modification of /etc/ld.so.preload to load a malicious shared object is a hallmark of a userland rootkit. The dynamic linker preloads the library into every process, allowing it to hook system calls like readdir and open, which hides files and processes and manipulates command output. This technique is stealthy because it operates in userland without kernel modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cron job persistence to maintain access

    Why it's wrong here

    Cron job persistence involves adding entries to crontab files to execute malicious code on a schedule. It does not modify /etc/ld.so.preload or cause commands like ls and ps to return manipulated output. While cron is a common persistence mechanism, the specific artifacts described here are consistent with a userland rootkit using dynamic linker preloading.

  • ✗

    SUID binary exploitation to escalate privileges

    Why it's wrong here

    SUID binary exploitation involves abusing a program with the setuid bit to gain higher privileges, often resulting in a root shell. It does not involve modifying /etc/ld.so.preload or hooking library calls to manipulate command output. The observed file modification and command output manipulation point to a userland rootkit, not privilege escalation via SUID.

  • ✗

    Kernel module rootkit loaded via insmod

    Why it's wrong here

    A kernel module rootkit would be loaded with insmod or modprobe and would appear in lsmod output. The scenario describes modification of /etc/ld.so.preload and userland command manipulation, which indicates a userland rootkit rather than a kernel module. Kernel rootkits are more powerful but leave different artifacts, such as loaded modules and modified syscall tables.

  • ✓

    Userland rootkit using LD_PRELOAD to hook library calls

    Why this is correct

    Modifying /etc/ld.so.preload to load a malicious shared object causes the dynamic linker to preload that library into every process. The library can hook functions like readdir and open to hide files and processes, producing manipulated output from commands like ls and ps. This is a classic userland rootkit technique on Linux that does not require kernel modifications.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.