Courseiva

GPEN Domain Escalation and Persistence Practice Question

During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?

⚠ Common exam trap

Candidates often suggest placing keys in the user's home directory root or a random folder, forgetting that SSH specifically requires the .ssh directory and authorized_keys file to function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

~/.ssh/authorized_keys

The ~/.ssh/authorized_keys file is the standard location for SSH public keys. By appending a public key to this file, an attacker can log in via SSH using the corresponding private key without needing a password. This is a common, reliable, and stealthy persistence method on Linux systems that allows for repeated, automated access to the compromised server throughout the duration of the test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ~/.ssh/known_hosts

    Why it's wrong here

    The known_hosts file stores the public keys of servers that the client has previously connected to, not the authorized keys for user authentication. Adding an entry here does nothing to facilitate persistent access for the attacker; it only affects the client's ability to verify the identity of other hosts.

  • ✓

    ~/.ssh/authorized_keys

    Why this is correct

    The authorized_keys file contains the public keys allowed to authenticate for a given user account. By adding a key here, you create a persistent access point. The file and the ~/.ssh directory must have correct permissions (e.g., 600 for the file) for the SSH daemon to accept the key.

  • ✗

    /etc/ssh/ssh_config

    Why it's wrong here

    The ssh_config file is the system-wide client configuration file. Modifying it would affect all outbound SSH connections from the server, which is not the goal of establishing persistence for inbound access. Furthermore, changing this file requires administrative privileges and is highly visible to system administrators and security monitoring.

  • ✗

    /etc/shadow

    Why it's wrong here

    The /etc/shadow file stores hashed user passwords. It does not store SSH public keys. Modifying this file is a different technique aimed at cracking or changing passwords, not at adding an SSH key for persistent access, and it is significantly more likely to be detected by integrity monitoring systems.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.