GPEN Domain Escalation and Persistence Practice Question
Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?
⚠ Common exam trap
Candidates frequently confuse persistence with lateral movement or privilege escalation, failing to recognize that persistence specifically refers to maintaining access across system disruptions like reboots or logouts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining a presence on the system through system restarts.
Persistence ensures that an attacker maintains access to a system even after reboots, credential changes, or other disruptions. This is achieved through various techniques like scheduled tasks, registry modifications, or backdoored services. Persistence is vital for long-term intelligence gathering and ensures that the attacker remains within the environment to pursue their objectives despite potential detection or system maintenance activities performed by legitimate users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Gaining initial access to a target network via phishing.
Why it's wrong here
Initial access is the first stage where an attacker gains a foothold in the network. This is separate from persistence, which occurs after the initial compromise to ensure the attacker does not lose access once the session is terminated or the target system is rebooted by the user.
- ✓
Maintaining a presence on the system through system restarts.
Why this is correct
Persistence is specifically defined as the mechanism used to maintain a foothold on a system across reboots and other events. It allows the attacker to regain access without having to re-exploit the initial vulnerability, which might have been patched or otherwise remediated since the initial entry was gained.
- ✗
Exfiltrating sensitive data to an external server.
Why it's wrong here
Exfiltration is the act of removing data from the target network. This is usually the final stage of an attack and is distinct from persistence, which focuses on maintaining access to the target rather than the movement of data out of the environment or the stealing of information.
- ✗
Encrypting the system for ransomware purposes.
Why it's wrong here
Ransomware is an impact-oriented action that disrupts system availability. Persistence is about long-term access, whereas ransomware aims to cause damage or demand payment. While ransomware might use persistence to stay active, the two are distinct concepts within the kill chain, and one is not synonymous with the other.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.