hardMultiple Select
CISSP Practice Question: Which THREE of the following are common…
Which THREE of the following are common indicators of a privilege escalation attack? (Choose three.)
⚠ Common exam trap
ISC2 often tests the distinction between general attack symptoms (like network traffic spikes or performance drops) and specific indicators that directly evidence the privilege escalation technique itself, leading candidates to over-select broad, non-specific options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creation of new user accounts with administrative privileges
Option A is correct because attackers who achieve privilege escalation often create new local or domain accounts and add them to administrative groups (e.g., Administrators, Domain Admins, or sudoers) to establish persistent, high-privilege access. Option D is correct because privilege escalation commonly involves tampering with system files or registry keys—such as modifying HKLM\SYSTEM or service binaries—to weaken security controls, disable protections like UAC, or enable persistence. Option E is correct because processes running under SYSTEM, root, or other elevated contexts that are unexpected (e.g., cmd.exe spawned by a service, or unusual binaries with high integrity levels) are a classic sign that an attacker has escalated privileges. Option B is not specific to privilege escalation, since higher-than-normal network traffic more often indicates data exfiltration, scanning, or DoS activity rather than elevation itself. Option C is likewise a generic symptom that can result from malware, resource exhaustion, or many other causes, so it is not a reliable indicator of privilege escalation specifically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creation of new user accounts with administrative privileges
Why this is correct
Once an attacker successfully gains elevated privileges, creating new user accounts with administrative rights is a common tactic to establish a persistent backdoor. This allows them to maintain access to the compromised system even if the original exploit vector is patched or the initial compromised user account is disabled. It provides a reliable, independent method for future access, making detection and remediation more challenging for defenders.
- ✗
Higher-than-normal network traffic
Why it's wrong here
While anomalous network traffic can certainly indicate malicious activity, it is not a direct or primary indicator of privilege escalation itself. Privilege escalation typically involves local system operations to gain higher access rights, which may not generate significant external network traffic. Instead, increased network traffic is more commonly associated with post-escalation activities such as command and control (C2) communications, data exfiltration, or lateral movement.
- ✗
System performance degradation
Why it's wrong here
System performance degradation is a very broad symptom that can result from numerous benign or malicious causes, such as resource-intensive legitimate applications, hardware issues, or denial-of-service attacks. While some privilege escalation exploits might temporarily consume system resources, it is not a specific or reliable indicator of the escalation event itself. Its generic nature makes it an unreliable primary detection method for privilege escalation.
- ✓
Modification of system files or registry keys
Why this is correct
Attackers frequently modify critical system files (e.g., executables, libraries) or registry keys (e.g., Run keys, service configurations) after achieving privilege escalation. These modifications are often performed to establish persistence, disable security controls, or inject malicious code that executes with elevated privileges upon system startup or specific events. Such unauthorized changes to core system components are a strong indicator of a successful compromise and privilege escalation.
- ✓
Unusual processes running under elevated privileges
Why this is correct
The presence of processes running with elevated privileges (e.g., SYSTEM, root, Administrator) that are not part of the normal operating system or legitimate application functions is a strong indicator of privilege escalation. This often occurs when an attacker successfully exploits a vulnerability to launch a shell or execute arbitrary code with higher permissions than the initial compromised user. Observing such unusual processes directly demonstrates that an escalation of privileges has taken place.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.