Courseiva

GPEN · topic practice

Domain Escalation and Persistence practice questions

This domain covers post-exploitation tradecraft on Windows/Active Directory: privilege escalation to Domain Admin, credential abuse (Kerberos, DCSync, LSASS), and durable persistence. GPEN tests whether you can select methods that survive reboots and password resets, and recognize why artifacts like backdoor accounts, Golden Tickets, and Skeleton Keys are dangerous if left behind.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Domain Escalation and Persistence

What the exam tests

What to know about Domain Escalation and Persistence

You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.

Golden Ticket and KRBTGT hash abuse for domain-wide Kerberos persistence

DCSync replication rights abuse to extract domain credential hashes

Scheduled tasks, services, and WMI event subscriptions for reboot-surviving persistence

Skeleton Key and AdminSDHolder for stealthy Domain Admin persistence

Watch out for

Common Domain Escalation and Persistence exam traps

  • ▸Confusing Golden Ticket with Silver Ticket: Golden uses KRBTGT and forges TGTs; Silver uses a service account hash and forges service tickets.
  • ▸Assuming a Golden Ticket dies with a Domain Admin password reset; only KRBTGT resets (twice) invalidate it.
  • ▸Leaving backdoor accounts, Skeleton Key, or DSRM changes in place after the engagement, creating real risk and failing cleanup.

Practice set

Domain Escalation and Persistence questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. As a penetration tester, you discover this registry key. What is the primary security implication of this finding regarding persistence?

Exhibit

C:\> reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Updater"="C:\\ProgramData\\App\\Update.exe"

Refer to the exhibit. What is the security concern regarding this service configuration?

Exhibit

C:\> sc qc "HiddenService"
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: HiddenService
        TYPE               : 10 WIN32_OWN_PROCESS
        START_TYPE         : 2 AUTO_START
        BINARY_PATH_NAME   : C:\Windows\System32\svchost.exe -k netsvcs
        SERVICE_START_NAME : LocalSystem

During a penetration test on an Active Directory environment, you have compromised a workstation and want to maintain persistence across reboots without modifying the registry or creating scheduled tasks. You have local administrator rights. Which method is most appropriate?

A penetration tester has gained Domain Admin access and wants to establish persistence on a Windows domain. The tester must ensure the persistence survives a reboot of the domain controller and remains undetected by standard security audits. Which TWO of the following techniques best meet these requirements? (Choose two.)

During a penetration test, you gain access to a Linux server and want to establish persistence by creating a new user account with root privileges. Which of the following methods is most likely to succeed and remain stealthy?

During a penetration test on a Windows domain-joined workstation, you have obtained local administrator privileges. You want to establish persistence that survives reboots and allows you to execute a payload when any user logs on, while minimizing the chance of detection by common security tools. Which of the following methods best meets these requirements?

You have compromised a Windows workstation that is part of a domain. You want to establish persistence that survives reboots and does not require administrative privileges. Which of the following techniques is most appropriate?

After exploiting a Linux server, you want to ensure that your backdoor remains accessible even if the system is rebooted. You decide to use a cron job. Which of the following cron locations would execute your job at system startup, regardless of which user is logged in?

You have compromised a Linux server and escalated to root. To maintain persistence, you want to create a backdoor that executes whenever a specific user logs in via SSH, but you want to avoid modifying system-wide files that might be monitored. Which of the following methods best achieves this?

After compromising a Windows domain controller, you want to maintain persistent access even if your initial account password is changed. Which of the following techniques best achieves this while remaining relatively stealthy?

You have gained access to a Windows workstation that is part of an Active Directory domain. You want to establish persistence that leverages the domain infrastructure, allowing you to re-authenticate as the compromised user even if their password is changed. Which two of the following techniques best achieve this? (Choose two.)

During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?

Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?

When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?

Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?

Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?

Exhibit

C:\> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name           Description                          State
======================== ==================================== ========
SeDebugPrivilege         Debug programs and processes         Enabled

Which THREE of the following are valid techniques for privilege escalation on a Linux system?

Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?

What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?

Which TWO of the following are common indicators that a Windows system has been compromised with persistence?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Domain Escalation and Persistence sessions

Start a Domain Escalation and Persistence only practice session

Every question in these sessions is drawn from the Domain Escalation and Persistence domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Domain Escalation and Persistence?
You must be able to escalate to Domain Admin and establish persistence that survives reboots and Domain Admin password resets, then remove it. The critical point: only resetting the KRBTGT password twice invalidates a Golden Ticket.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Domain Escalation and Persistence questions in a focused session?
Yes — the session launcher on this page draws every question from the Domain Escalation and Persistence domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.