GSEC Malicious Code and Exploit Mitigation Practice Question
A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to determine how the attacker is maintaining access after reboots. Which artifact should the responder check first to identify a persistent mechanism on this Linux host?
⚠ Common exam trap
The trap here is focusing on logs that prove the intrusion occurred instead of configuration artifacts that explain how access persists after a restart.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The crontab entries for all users and the /etc/cron.* directories.
On Linux, cron jobs are a primary persistence mechanism because they run on a schedule and survive reboots. An attacker with web shell access often adds a crontab entry or a file in /etc/cron.d that re-downloads a payload or opens a reverse shell. Checking all user crontabs and the system cron directories is therefore the most direct first step to identify how access is maintained, ahead of logs that only show activity rather than configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The crontab entries for all users and the /etc/cron.* directories.
Why this is correct
Scheduled tasks are one of the most common Linux persistence mechanisms, and checking every user's crontab plus the system cron directories reveals jobs that re-establish access or re-download payloads at regular intervals. Because cron survives reboots, it directly answers how the attacker maintains access. Root crontabs and files under /etc/cron.d, /etc/cron.hourly, and related directories are the highest-value locations to inspect first.
- ✗
The /etc/passwd file for accounts with UID 0.
Why it's wrong here
Checking /etc/passwd for extra UID 0 accounts is a good practice because attackers sometimes add a backdoor root user, but it is only one persistence method and often a noisy one. Many attackers prefer scheduled tasks, SSH authorized_keys, or systemd services, which leave /etc/passwd untouched. This file is worth reviewing, but it is not the most likely or highest-value first artifact for reboot-persistent access on a compromised Linux web server.
- ✗
The Apache access log for POST requests to the vulnerable PHP script.
Why it's wrong here
The Apache access log can confirm exploitation and show web shell command traffic, which is valuable for understanding the intrusion. However, it records request history, not persistence configuration, and log rotation may have removed older entries. Since the question asks how the attacker maintains access across reboots, the access log is not the right first artifact even though it helps establish the initial compromise.
- ✗
The /var/log/auth.log file for failed SSH login attempts.
Why it's wrong here
The auth.log records authentication events such as SSH logins and sudo usage, which can show initial access or privilege escalation but does not enumerate persistence mechanisms. A web shell attacker may never touch SSH at all, so the absence of suspicious logins does not rule out persistence. This file is useful for timeline reconstruction but is not the first place to identify how access survives a reboot.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.