GPEN · domain
Domain Escalation and Persistence
This domain covers post-exploitation tradecraft on Windows/Active Directory: privilege escalation to Domain Admin, credential abuse (Kerberos, DCSync, LSASS), and durable persistence. GPEN tests whether you can select methods that survive reboots and password resets, and recognize why artifacts like backdoor accounts, Golden Tickets, and Skeleton Keys are dangerous if left behind.
Focused practice
Practice Domain Escalation and Persistence questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Domain Escalation and Persistence
You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.
Golden Ticket and KRBTGT hash abuse for domain-wide Kerberos persistence
DCSync replication rights abuse to extract domain credential hashes
Scheduled tasks, services, and WMI event subscriptions for reboot-surviving persistence
Skeleton Key and AdminSDHolder for stealthy Domain Admin persistence
Watch out for
Common Domain Escalation and Persistence exam traps
- ▸Confusing Golden Ticket with Silver Ticket: Golden uses KRBTGT and forges TGTs; Silver uses a service account hash and forges service tickets.
- ▸Assuming a Golden Ticket dies with a Domain Admin password reset; only KRBTGT resets (twice) invalidate it.
- ▸Leaving backdoor accounts, Skeleton Key, or DSRM changes in place after the engagement, creating real risk and failing cleanup.
Question index
All Domain Escalation and Persistence questions (16)
Click any question to see the full explanation, or start a practice session above.
During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?
Medium2Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?
Medium3During a penetration test on a Linux system, you have gained root access and want to ensure that your backdoor survives system reboots. Which of the following methods is the most reliable and commonly used for this purpose?
Easy4During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
Medium5Which TWO of the following are common indicators that a Windows system has been compromised with persistence?
Medium6A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?
Hard7Which THREE of the following are valid techniques for privilege escalation on a Linux system?
Hard8Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?
Medium9Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?
Medium10Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?
Medium11When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?
Hard12You have obtained domain administrator credentials during a penetration test. To maintain stealthy persistence on a Windows domain controller, you decide to abuse Kerberos. Which method allows you to authenticate as any user without knowing their password, and is a known persistence technique?
Medium13What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?
Medium14You have obtained Domain Admin credentials during an internal penetration test. To ensure continued access even if the compromised user's password is changed, you decide to create a Golden Ticket. Which artifact is required to forge a Golden Ticket?
Medium15During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?
Hard16Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?
EasyOther domains
All GPEN exam domains
Frequently asked questions
- What does the Domain Escalation and Persistence domain cover on the GPEN exam?
- You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.
- How many questions are in this domain?
- This page lists all 16 Domain Escalation and Persistence questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Domain Escalation and Persistence questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.