Courseiva
hardMultiple Select

CISSP Practice Question: Which THREE of the following are common…

Which THREE of the following are common indicators of a privilege escalation attack? (Choose three.)

⚠ Common exam trap

ISC2 often tests the distinction between general attack symptoms (like network traffic spikes or performance drops) and specific indicators that directly evidence the privilege escalation technique itself, leading candidates to over-select broad, non-specific options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creation of new user accounts with administrative privileges

Option A is correct because attackers who achieve privilege escalation often create new local or domain accounts and add them to administrative groups (e.g., Administrators, Domain Admins, or sudoers) to establish persistent, high-privilege access. Option D is correct because privilege escalation commonly involves tampering with system files or registry keys—such as modifying HKLM\SYSTEM or service binaries—to weaken security controls, disable protections like UAC, or enable persistence. Option E is correct because processes running under SYSTEM, root, or other elevated contexts that are unexpected (e.g., cmd.exe spawned by a service, or unusual binaries with high integrity levels) are a classic sign that an attacker has escalated privileges. Option B is not specific to privilege escalation, since higher-than-normal network traffic more often indicates data exfiltration, scanning, or DoS activity rather than elevation itself. Option C is likewise a generic symptom that can result from malware, resource exhaustion, or many other causes, so it is not a reliable indicator of privilege escalation specifically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Creation of new user accounts with administrative privileges

    Why this is correct

    Once an attacker successfully gains elevated privileges, creating new user accounts with administrative rights is a common tactic to establish a persistent backdoor. This allows them to maintain access to the compromised system even if the original exploit vector is patched or the initial compromised user account is disabled. It provides a reliable, independent method for future access, making detection and remediation more challenging for defenders.

  • ✗

    Higher-than-normal network traffic

    Why it's wrong here

    While anomalous network traffic can certainly indicate malicious activity, it is not a direct or primary indicator of privilege escalation itself. Privilege escalation typically involves local system operations to gain higher access rights, which may not generate significant external network traffic. Instead, increased network traffic is more commonly associated with post-escalation activities such as command and control (C2) communications, data exfiltration, or lateral movement.

  • ✗

    System performance degradation

    Why it's wrong here

    System performance degradation is a very broad symptom that can result from numerous benign or malicious causes, such as resource-intensive legitimate applications, hardware issues, or denial-of-service attacks. While some privilege escalation exploits might temporarily consume system resources, it is not a specific or reliable indicator of the escalation event itself. Its generic nature makes it an unreliable primary detection method for privilege escalation.

  • ✓

    Modification of system files or registry keys

    Why this is correct

    Attackers frequently modify critical system files (e.g., executables, libraries) or registry keys (e.g., Run keys, service configurations) after achieving privilege escalation. These modifications are often performed to establish persistence, disable security controls, or inject malicious code that executes with elevated privileges upon system startup or specific events. Such unauthorized changes to core system components are a strong indicator of a successful compromise and privilege escalation.

  • ✓

    Unusual processes running under elevated privileges

    Why this is correct

    The presence of processes running with elevated privileges (e.g., SYSTEM, root, Administrator) that are not part of the normal operating system or legitimate application functions is a strong indicator of privilege escalation. This often occurs when an attacker successfully exploits a vulnerability to launch a shell or execute arbitrary code with higher permissions than the initial compromised user. Observing such unusual processes directly demonstrates that an escalation of privileges has taken place.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.