GPEN Domain Escalation and Persistence Practice Question
Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?
⚠ Common exam trap
Candidates often assume cron persistence only involves modifying the user crontab. They overlook system-wide directories like /etc/cron.d/, which run as root and are frequently used for stealthy persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating a new file in /etc/cron.d/ with an execution trigger.
Cron is a time-based job scheduler. Attackers utilize /etc/crontab or specific user crontabs to execute malicious scripts at defined intervals. This ensures that even if a session is terminated, the attacker's payload re-executes. Monitoring cron directories and user-specific crontab files is essential for detection, as these are frequent targets for maintaining persistent access on Linux servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating a new file in /etc/cron.d/ with an execution trigger.
Why this is correct
Files placed in /etc/cron.d/ are automatically parsed by the cron daemon. This is a common method for attackers to inject persistent tasks because it does not require modifying existing crontab entries, making it slightly more stealthy and easier to manage during the post-exploitation phase of an engagement.
- ✗
Modifying the /etc/shadow file to grant root access.
Why it's wrong here
Modifying /etc/shadow is a method for privilege escalation through credential manipulation, not a persistence mechanism related to cron jobs. While effective for gaining access, it does not involve the time-based scheduling functionality provided by the cron daemon and is highly visible to integrity monitoring systems.
- ✓
Adding an entry to the crontab of a high-privilege service account.
Why this is correct
Scheduling tasks within the crontab of accounts like root or service users allows the attacker to execute their code with the privileges of that specific user. This is a highly effective way to maintain persistence and potentially perform automated lateral movement or data exfiltration tasks.
- ✗
Replacing the bash shell binary with a malicious version.
Why it's wrong here
Replacing the system shell is an extreme persistence technique that risks system instability. It is not a method involving cron jobs, which are designed for task scheduling. This approach is easily detected by file integrity monitoring tools that check the checksums of critical system binaries regularly.
- ✗
Setting a boot-time delay in the global /etc/environment file.
Why it's wrong here
/etc/environment is used for setting system-wide environment variables, not for scheduling recurring tasks. Setting a delay here would not achieve persistence through cron, as it does not control the execution of processes or scripts over time in the manner that the cron daemon is configured to do.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.