GSEC Endpoint Security Practice Question
A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?
⚠ Common exam trap
The trap here is focusing on user account files or logs, when the question specifically asks for scheduled tasks that run automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/crontab and the /etc/cron.* directories
System-wide cron files and directories are the primary location for scheduled tasks on Linux. Attackers frequently add entries to /etc/crontab or /etc/cron.* to run malicious commands at boot or regular intervals, ensuring persistence across reboots. Examining these files first aligns with the goal of identifying how the attacker maintains access after a restart.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/hosts
Why it's wrong here
/etc/hosts maps hostnames to IP addresses for local name resolution. An attacker could modify it to redirect traffic or block security updates, but it does not contain scheduled tasks or commands that execute automatically. It is not a persistence mechanism for running code at boot or on a schedule. Therefore, it is not the artifact to examine first when looking for scheduled tasks.
- ✓
/etc/crontab and the /etc/cron.* directories
Why this is correct
The /etc/crontab file and the /etc/cron.* directories contain system-wide scheduled tasks that run automatically at specified intervals or at boot. Attackers commonly add entries here to re-establish access after a reboot. Reviewing these locations is a primary step in identifying persistence via scheduled tasks. Other cron locations such as user crontabs also matter, but the system-wide files are the first place to check for reboot-persistent jobs.
- ✗
/var/log/auth.log
Why it's wrong here
/var/log/auth.log records authentication events, including successful and failed logins and sudo usage. It can help trace the attacker's actions but does not store scheduled tasks. While it might show when a cron job ran or a user logged in, it does not contain the cron configuration itself. The team needs to find the persistence mechanism, so this log is a supporting artifact, not the primary one for scheduled tasks.
- ✗
/etc/passwd
Why it's wrong here
/etc/passwd stores user account information such as usernames, UIDs, home directories, and login shells. While an attacker might add a rogue account, the file does not contain scheduled tasks or commands that run automatically at boot. Examining it is useful for finding unauthorized users, but it does not reveal cron-based persistence. The scenario specifically asks for scheduled tasks, so this file is not the best first artifact.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.