GPEN Domain Escalation and Persistence Practice Question
What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?
⚠ Common exam trap
Candidates often focus on the technical 'how' of the backdoor. They overlook the professional and ethical imperative of cleanup, which is critical for avoiding long-term security liabilities for clients.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The account acts as a persistent entry point for unauthorized parties.
Leaving a backdoor account creates an unauthorized access path that persists after the engagement ends. This violates the principle of 'cleanup' and can lead to security breaches by third parties who discover the account. It represents a significant liability and risk for the client, as an unsecured backdoor account is a prime target for malicious actors looking to exploit the environment without further effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The account may trigger an automated system update.
Why it's wrong here
Backdoor accounts do not influence system update processes. Updates are managed by system services or administrators and are independent of user account existence. The danger is related to unauthorized access and persistence, not the operational behavior of the system's patching mechanisms or the management of system software updates.
- ✓
The account acts as a persistent entry point for unauthorized parties.
Why this is correct
A backdoor account provides a known credential or access method that an attacker can use to return to the system. If this is not removed, it remains a permanent security hole that can be exploited long after the legitimate testing window has closed, causing significant risk to the organization.
- ✗
The system performance will degrade due to the account.
Why it's wrong here
A single user account has negligible impact on system performance. The primary concern is security, not the system's resource utilization. Identifying this as a performance issue misunderstands the nature of the risk, which is centered on unauthorized access rather than the consumption of CPU or memory by the OS.
- ✗
The account automatically encrypts data in the directory.
Why it's wrong here
Standard user accounts do not possess inherent encryption capabilities. This is a functional misunderstanding of how user accounts interact with the operating system and data security. The risk associated with a backdoor account is access control and unauthorized entry, not the automatic transformation of data via cryptographic means.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.