Courseiva

CCNA Domain Escalation and Persistence Questions

16 questions · Domain Escalation and Persistence · All types, answers revealed

1
MCQmedium

During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?

A.~/.ssh/known_hosts
B.~/.ssh/authorized_keys
C./etc/ssh/ssh_config
D./etc/shadow
AnswerB

The authorized_keys file contains the public keys allowed to authenticate for a given user account. By adding a key here, you create a persistent access point. The file and the ~/.ssh directory must have correct permissions (e.g., 600 for the file) for the SSH daemon to accept the key.

Why this answer

The ~/.ssh/authorized_keys file is the standard location for SSH public keys. By appending a public key to this file, an attacker can log in via SSH using the corresponding private key without needing a password. This is a common, reliable, and stealthy persistence method on Linux systems that allows for repeated, automated access to the compromised server throughout the duration of the test.

Exam trap

Candidates often suggest placing keys in the user's home directory root or a random folder, forgetting that SSH specifically requires the .ssh directory and authorized_keys file to function.

2
MCQmedium

Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?

A.Adding a startup shortcut to the All Users Startup folder.
B.Creating a WMI event subscription for system events.
C.Modifying the existing service binary to include a backdoor.
D.Running a scheduled task with a visible command prompt window.
AnswerB

WMI event subscriptions allow attackers to execute code when specific system conditions are met. Because these subscriptions are stored in the WMI repository rather than standard registry keys, they evade basic persistence checks, making them a highly effective and stealthy method for maintaining long-term access to a Windows system.

Why this answer

Persistence is often detected via common registry keys like Run or RunOnce. Using Windows Management Instrumentation (WMI) event subscriptions allows for persistence that is harder to detect. By creating an EventFilter and EventConsumer, an attacker can trigger a malicious script based on system events, such as a specific time or system uptime, bypassing traditional registry-based forensic analysis and providing a robust, fileless-like execution method.

Exam trap

Candidates often suggest common techniques like Run keys or startup folders, overlooking that these are heavily monitored. WMI is chosen specifically for its ability to operate stealthily without registry modifications.

3
MCQeasy

During a penetration test on a Linux system, you have gained root access and want to ensure that your backdoor survives system reboots. Which of the following methods is the most reliable and commonly used for this purpose?

A.Create a systemd service unit that runs your payload at startup.
B.Add your payload to the /etc/rc.local file.
C.Add a cron job with @reboot schedule that executes your payload.
D.Modify the root user's .bash_profile to execute your payload on login.
AnswerA

Systemd is the default init system on most modern Linux distributions, and creating a service unit ensures your payload runs at system startup. It is reliable, persistent across reboots, and can be configured to run as root. This method is commonly used by attackers and is less likely to be removed accidentally. It provides a robust backdoor that starts early in the boot process.

Why this answer

Creating a systemd service unit is the most reliable method for ensuring a backdoor runs at system startup on modern Linux distributions. Systemd is the standard init system, and service units are executed automatically during boot. This method is persistent, can run with root privileges, and is less likely to be disabled by default than legacy mechanisms like rc.local or cron @reboot.

Exam trap

The trap here is assuming that legacy methods like rc.local or cron @reboot are universally reliable, when in fact systemd is the standard on most current Linux systems and provides more consistent startup execution.

4
MCQmedium

During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?

A.Overwrite the existing service executable with a custom payload.
B.Modify the service configuration using the sc config command.
C.Place a malicious binary at the first detected space-delimited path segment.
D.Inject a DLL into the running service process memory space.
AnswerC

Windows attempts to execute the path segment before the space if no quotes are present. By placing a malicious executable at that specific location with the appropriate name, the service manager will execute your file instead of the intended one, running your code with the service's high-privilege context.

Why this answer

Unquoted service paths exist when the service binary path contains spaces and lacks quotes. Windows interprets the path incorrectly, searching for intermediate executables. Placing a malicious binary at the identified path allows it to execute with SYSTEM privileges upon service restart.

This technique is critical for privilege escalation as it exploits inherent Windows path resolution logic, often bypassing standard user restrictions if the directory has weak permissions.

Exam trap

Candidates often try to modify the existing service binary. They forget that the vulnerability relies on the path resolution order, requiring the placement of a new file, not modification.

5
Multi-Selectmedium

Which TWO of the following are common indicators that a Windows system has been compromised with persistence?

Select 2 answers
A.Presence of unknown services running as SYSTEM.
B.Increased usage of the CPU by the system kernel.
C.Unexpected files in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder.
D.Changes to the system's desktop wallpaper.
E.A high number of failed login attempts in the event log.
AnswersA, C

Malware often installs itself as a service to ensure it runs with high privileges upon system startup. An unrecognized service running as SYSTEM is a major red flag that warrants immediate investigation, as it is a common method for achieving both persistence and privilege escalation on Windows servers.

Why this answer

Indicators of persistence in Windows include unusual entries in startup folders, unrecognized services set to auto-start, and suspicious registry keys. Monitoring these areas is standard procedure for incident response and threat hunting. Detecting these markers early allows defenders to disrupt the attacker's ability to maintain access, effectively ending the persistence phase and forcing the attacker to re-establish a foothold, which increases the likelihood of detection.

Exam trap

Candidates often look only for obvious malware files. They fail to recognize that legitimate-looking services or startup entries running as SYSTEM are the most reliable indicators of persistent compromise.

6
MCQhard

A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?

A.Deploy a Golden Ticket by forging a Kerberos TGT using the krbtgt account hash.
B.Install a service on a domain controller that runs as Local System and starts automatically.
C.Create a new user account with Domain Admin membership and hide it from the default Users container.
D.Add an ACL to the Domain Admins group granting Full Control to a controlled user account.
AnswerA

A Golden Ticket is a forged TGT signed with the krbtgt account's NTLM hash. It remains valid until the krbtgt password is changed twice, so it survives normal Domain Admin password resets and reboots. Because it is generated on demand and not written to disk, it is stealthy and does not rely on a persistent binary, matching the scenario's constraints precisely.

Why this answer

A Golden Ticket is forged from the krbtgt hash and validated by the domain's Kerberos service until the krbtgt password is reset twice. This makes it resilient to Domain Admin password changes and reboots, and because it is generated on demand without a persistent binary, it is stealthier than account creation, new services, or ACL modifications. It directly satisfies the scenario's requirements.

Exam trap

The trap here is assuming that any Domain Admin-level access survives a password reset; only techniques tied to the krbtgt hash or similar secrets withstand that specific remediation.

7
Multi-Selecthard

Which THREE of the following are valid techniques for privilege escalation on a Linux system?

Select 3 answers
A.Exploiting a binary with the SUID bit set to root.
B.Configuring a new user account with no password.
C.Abusing sudo permissions that allow specific command execution as root.
D.Exploiting kernel vulnerabilities to gain root-mode execution.
E.Renaming the /etc/passwd file to /etc/shadow.
AnswersA, C, D

SUID binaries owned by root execute with root privileges. If the binary is vulnerable to buffer overflows or path injection, an attacker can hijack the execution flow to launch a root shell. This is a classic and highly effective privilege escalation path on many legacy Linux systems.

Why this answer

Privilege escalation involves exploiting misconfigurations to gain higher access. Common vectors include exploiting SUID binaries, abusing SUDO rules that allow commands to run as root without passwords, and exploiting kernel vulnerabilities that allow arbitrary code execution in kernel mode. Understanding these vectors is crucial for identifying how an unprivileged user can transition to root and maintain control over the compromised Linux infrastructure.

Exam trap

Candidates often choose standard user permission configurations or weak password policies, failing to recognize specific structural mechanisms like SUID and sudoers entries.

8
MCQmedium

Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?

A.They automatically bypass all firewall rules.
B.They allow for granular control over execution triggers.
C.They hide the task from the Task Scheduler GUI.
D.They are the only way to execute scripts at boot.
AnswerB

Scheduled tasks offer diverse triggers like system startup, user login, or specific time intervals. This granularity allows attackers to time their activity for periods of low system usage or to ensure their code runs reliably after reboots, maximizing the longevity of the persistent connection to the target system.

Why this answer

Scheduled tasks are highly configurable, allowing attackers to define specific triggers, user contexts, and repeat intervals. They are natively supported by Windows and appear as legitimate tasks, making them appear less suspicious than custom registry modifications. The ability to run tasks as SYSTEM or as a specific user provides attackers with flexibility in executing their payloads while maintaining a low profile within the system's management tools.

Exam trap

Candidates often think scheduled tasks are only for running things at specific times, failing to realize they offer granular control over triggers like idle time or network connectivity.

9
Multi-Selectmedium

Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?

Select 2 answers
A.Creating a new file in /etc/cron.d/ with an execution trigger.
B.Modifying the /etc/shadow file to grant root access.
C.Adding an entry to the crontab of a high-privilege service account.
D.Replacing the bash shell binary with a malicious version.
E.Setting a boot-time delay in the global /etc/environment file.
AnswersA, C

Files placed in /etc/cron.d/ are automatically parsed by the cron daemon. This is a common method for attackers to inject persistent tasks because it does not require modifying existing crontab entries, making it slightly more stealthy and easier to manage during the post-exploitation phase of an engagement.

Why this answer

Cron is a time-based job scheduler. Attackers utilize /etc/crontab or specific user crontabs to execute malicious scripts at defined intervals. This ensures that even if a session is terminated, the attacker's payload re-executes.

Monitoring cron directories and user-specific crontab files is essential for detection, as these are frequent targets for maintaining persistent access on Linux servers.

Exam trap

Candidates often assume cron persistence only involves modifying the user crontab. They overlook system-wide directories like /etc/cron.d/, which run as root and are frequently used for stealthy persistence.

10
MCQmedium

Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?

A.Attempt to restart the system to reset privileges.
B.Use the privilege to dump process memory, such as LSASS.
C.Disable the privilege to ensure system stability.
D.Install a rootkit to hide the enabled privilege.
AnswerB

SeDebugPrivilege allows a user to debug any process. By attaching to the Local Security Authority Subsystem Service (LSASS), you can dump the memory to extract clear-text passwords or NTLM hashes, which are essential for escalating privileges within the local system and moving laterally across the Windows domain environment.

Why this answer

SeDebugPrivilege is a powerful right that allows a user to attach to any process, including those running as SYSTEM. This privilege is instrumental in privilege escalation, as it allows for memory dumping of LSASS to extract credentials or the injection of malicious code into high-privilege processes. Identifying this privilege enables the tester to move from a standard user context to a full system-level compromise effectively.

Exam trap

Candidates frequently mistake SeDebugPrivilege for an automatic root shell. They forget that while it grants high-level access to processes, it still requires manual interaction to dump memory or inject code.

11
MCQhard

When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?

A.It forces the file to run within a restricted sandbox environment.
B.It permits the file to execute with the owner's privileges.
C.It enables the file to be readable by all users on the system.
D.It automatically encrypts the file contents at rest.
AnswerB

When the SUID bit is set, the process runs as the owner of the file. If that owner is root, the process runs with root privileges. This behavior is intentional for specific system binaries, but it creates a vulnerability if the binary can be abused to perform unintended actions.

Why this answer

The SUID (Set User ID) bit allows a file to execute with the permissions of the file owner rather than the user executing it. If an attacker identifies a SUID file owned by root, they can potentially manipulate the execution flow to gain a root shell. This is a primary target for privilege escalation, as it permits users to circumvent standard permission constraints during execution.

Exam trap

Candidates often think SUID files are inherently malicious. They fail to understand that SUID is a legitimate feature that only becomes a security risk when applied to user-writable, root-owned files.

12
MCQmedium

You have obtained domain administrator credentials during a penetration test. To maintain stealthy persistence on a Windows domain controller, you decide to abuse Kerberos. Which method allows you to authenticate as any user without knowing their password, and is a known persistence technique?

A.Golden Ticket attack using the KRBTGT account hash.
B.Silver Ticket attack using a service account hash.
C.Skeleton Key attack by patching LSASS on the domain controller.
D.DCSync attack to replicate domain controller secrets.
AnswerA

A Golden Ticket is forged using the KRBTGT account's NTLM hash to create a TGT that grants access as any user. This provides long-term persistence because the KRBTGT hash remains valid until the password is changed twice. It is a well-known domain escalation and persistence technique.

Why this answer

The Golden Ticket attack is a powerful persistence technique because it allows an attacker with the KRBTGT hash to forge TGTs for any user, including domain admins, without needing their passwords. This access persists until the KRBTGT password is changed twice, making it highly stealthy and long-lasting.

Exam trap

The trap here is confusing DCSync, which extracts hashes, with the Golden Ticket, which uses the extracted KRBTGT hash to forge tickets for persistent access.

13
MCQmedium

What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?

A.The account may trigger an automated system update.
B.The account acts as a persistent entry point for unauthorized parties.
C.The system performance will degrade due to the account.
D.The account automatically encrypts data in the directory.
AnswerB

A backdoor account provides a known credential or access method that an attacker can use to return to the system. If this is not removed, it remains a permanent security hole that can be exploited long after the legitimate testing window has closed, causing significant risk to the organization.

Why this answer

Leaving a backdoor account creates an unauthorized access path that persists after the engagement ends. This violates the principle of 'cleanup' and can lead to security breaches by third parties who discover the account. It represents a significant liability and risk for the client, as an unsecured backdoor account is a prime target for malicious actors looking to exploit the environment without further effort.

Exam trap

Candidates often focus on the technical 'how' of the backdoor. They overlook the professional and ethical imperative of cleanup, which is critical for avoiding long-term security liabilities for clients.

14
MCQmedium

You have obtained Domain Admin credentials during an internal penetration test. To ensure continued access even if the compromised user's password is changed, you decide to create a Golden Ticket. Which artifact is required to forge a Golden Ticket?

A.A valid TGS for the Domain Controller.
B.The KRBTGT account's NTLM hash.
C.The Domain Admin user's NTLM hash.
D.The domain's Kerberos policy settings.
AnswerB

The KRBTGT account's NTLM hash is the secret used to sign all TGTs in the domain. With this hash, you can forge a TGT (Golden Ticket) that grants access as any user, including Domain Admin, and remains valid until the KRBTGT password is changed twice. This is the correct artifact because it is the foundation of Kerberos ticket signing.

Why this answer

A Golden Ticket is a forged Kerberos TGT signed with the KRBTGT account's NTLM hash. This hash is the ultimate secret in a Kerberos realm; with it, an attacker can impersonate any user, including Domain Admins, and maintain access even after password changes. The KRBTGT hash is obtained by compromising a Domain Controller and extracting it from memory or the NTDS.dit file.

Exam trap

The trap here is confusing a Golden Ticket with a Silver Ticket, which requires the service account's hash rather than the KRBTGT hash.

15
MCQhard

During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?

A.The Golden Ticket can be used to authenticate to any service in the domain without additional tickets.
B.The KRBTGT account has a weak password that can be brute-forced.
C.The KRBTGT password is rarely changed, so the Golden Ticket remains valid for its full lifetime.
D.The Golden Ticket is automatically renewed by the domain controller, extending its validity.
AnswerC

Because the KRBTGT password has not been changed in 5 years, the extracted hash will remain valid for a long time, allowing the Golden Ticket to be used until the password is changed twice. This makes the persistence highly durable and stealthy, as no password change is imminent.

Why this answer

In this scenario, the KRBTGT password's extreme age means the hash is unlikely to be rotated soon. Since Golden Tickets remain valid until the KRBTGT password is changed twice, the attacker can maintain access for years, making this a highly effective and stealthy persistence method.

Exam trap

The trap here is assuming that a Golden Ticket is automatically renewed or that its effectiveness depends on brute-forcing, when in fact it relies on the KRBTGT hash remaining unchanged.

16
MCQeasy

Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?

A.Gaining initial access to a target network via phishing.
B.Maintaining a presence on the system through system restarts.
C.Exfiltrating sensitive data to an external server.
D.Encrypting the system for ransomware purposes.
AnswerB

Persistence is specifically defined as the mechanism used to maintain a foothold on a system across reboots and other events. It allows the attacker to regain access without having to re-exploit the initial vulnerability, which might have been patched or otherwise remediated since the initial entry was gained.

Why this answer

Persistence ensures that an attacker maintains access to a system even after reboots, credential changes, or other disruptions. This is achieved through various techniques like scheduled tasks, registry modifications, or backdoored services. Persistence is vital for long-term intelligence gathering and ensures that the attacker remains within the environment to pursue their objectives despite potential detection or system maintenance activities performed by legitimate users.

Exam trap

Candidates frequently confuse persistence with lateral movement or privilege escalation, failing to recognize that persistence specifically refers to maintaining access across system disruptions like reboots or logouts.

Ready to test yourself?

Try a timed practice session using only Domain Escalation and Persistence questions.