GPEN Domain Escalation and Persistence Practice Question
During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?
⚠ Common exam trap
Candidates often suggest placing keys in the user's home directory root or a random folder, forgetting that SSH specifically requires the .ssh directory and authorized_keys file to function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
~/.ssh/authorized_keys
The ~/.ssh/authorized_keys file is the standard location for SSH public keys. By appending a public key to this file, an attacker can log in via SSH using the corresponding private key without needing a password. This is a common, reliable, and stealthy persistence method on Linux systems that allows for repeated, automated access to the compromised server throughout the duration of the test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
~/.ssh/known_hosts
Why it's wrong here
The known_hosts file stores the public keys of servers that the client has previously connected to, not the authorized keys for user authentication. Adding an entry here does nothing to facilitate persistent access for the attacker; it only affects the client's ability to verify the identity of other hosts.
- ✓
~/.ssh/authorized_keys
Why this is correct
The authorized_keys file contains the public keys allowed to authenticate for a given user account. By adding a key here, you create a persistent access point. The file and the ~/.ssh directory must have correct permissions (e.g., 600 for the file) for the SSH daemon to accept the key.
- ✗
/etc/ssh/ssh_config
Why it's wrong here
The ssh_config file is the system-wide client configuration file. Modifying it would affect all outbound SSH connections from the server, which is not the goal of establishing persistence for inbound access. Furthermore, changing this file requires administrative privileges and is highly visible to system administrators and security monitoring.
- ✗
/etc/shadow
Why it's wrong here
The /etc/shadow file stores hashed user passwords. It does not store SSH public keys. Modifying this file is a different technique aimed at cracking or changing passwords, not at adding an SSH key for persistent access, and it is significantly more likely to be detected by integrity monitoring systems.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.