During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?
The authorized_keys file contains the public keys allowed to authenticate for a given user account. By adding a key here, you create a persistent access point. The file and the ~/.ssh directory must have correct permissions (e.g., 600 for the file) for the SSH daemon to accept the key.
Why this answer
The ~/.ssh/authorized_keys file is the standard location for SSH public keys. By appending a public key to this file, an attacker can log in via SSH using the corresponding private key without needing a password. This is a common, reliable, and stealthy persistence method on Linux systems that allows for repeated, automated access to the compromised server throughout the duration of the test.
Exam trap
Candidates often suggest placing keys in the user's home directory root or a random folder, forgetting that SSH specifically requires the .ssh directory and authorized_keys file to function.