exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 243 discussion

Actual exam question from CompTIA's PT0-002
Question #: 243
Topic #: 1
[All PT0-002 Questions]

A penetration tester opened a reverse shell on a Linux web server and successfully escalated privileges to root. During the engagement, the tester noticed that another user logged in frequently as root to perform work tasks. To avoid disrupting this user’s work, which of the following is the BEST option for the penetration tester to maintain root-level persistence on this server during the test?

  • A. Add a web shell to the root of the website.
  • B. Upgrade the reverse shell to a true TTY terminal.
  • C. Add a new user with ID 0 to the /etc/passwd file.
  • D. Change the password of the root user and revert after the test.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Asq1400
5 months, 1 week ago
Selected Answer: C
This is C
upvoted 1 times
...
Etc_Shadow28000
10 months, 1 week ago
Selected Answer: C
C. Add a new user with ID 0 to the /etc/passwd file. Explanation: Adding a new user with ID 0 to the /etc/passwd file: • This method involves adding a new user with root privileges by modifying the /etc/passwd file. By giving this new user an ID of 0, the same as the root user, the penetration tester can create a backdoor user account that has root-level access without changing any existing user credentials or disrupting the legitimate user’s activities. This approach provides a stealthy and persistent way to maintain root access.
upvoted 3 times
...
041ba31
1 year, 1 month ago
Selected Answer: C
Adding a new user with UID 0 to the /etc/passwd file gives the penetration tester root-level access without altering the existing root account's password or behavior. This method ensures persistent access for the tester while allowing the legitimate root user to continue their work uninterrupted. It's a stealthy approach that maintains the penetration tester's access without directly impacting other users.
upvoted 2 times
...
vazq77
1 year, 4 months ago
Selected Answer: C
for sure
upvoted 1 times
...
lordguck
1 year, 5 months ago
C is correct as it establishes a persistent way to access the system.
upvoted 1 times
...
[Removed]
1 year, 5 months ago
Selected Answer: B
Hard question, but I am leaning towards B.
upvoted 1 times
Etc_Shadow28000
10 months, 1 week ago
B. Upgrade the reverse shell to a true TTY terminal: • Upgrading the reverse shell to a true TTY terminal improves the usability and interaction of the shell, but it does not inherently provide persistence. The reverse shell connection would still be temporary and could be lost if the session is closed or interrupted.
upvoted 1 times
...
...
matheusfmartins
1 year, 9 months ago
Selected Answer: C
C the best option
upvoted 2 times
...
kips
1 year, 9 months ago
Selected Answer: C
C is the best
upvoted 2 times
...
[Removed]
2 years ago
Selected Answer: B
The BEST option for the penetration tester to maintain root-level persistence on this server during the test without disrupting the work of the other user is to add a new user with ID 0 to the /etc/passwd file. By doing so, the penetration tester will have a persistent user account with root-level privileges that can be used to maintain access to the system, without changing the credentials of the original root user. This approach will allow the other user to continue working on the system without interruption, and the penetration tester can continue with the test as required. The other options listed would either not provide persistent access or could disrupt the work of the other user.
upvoted 2 times
...
cy_analyst
2 years, 1 month ago
Selected Answer: B
B, upgrading the reverse shell to a true TTY terminal, is the best choice from the available options. This option will allow the penetration tester to interact with the system in a more user-friendly way, without disrupting the work of the other user. Upgrading the reverse shell to a TTY terminal will create a new session that can be used independently of the user currently logged in as root. This option is less likely to be detected by system administrators, and does not involve making any permanent changes to the system.
upvoted 4 times
...
KingIT_ENG
2 years, 1 month ago
C is correct
upvoted 3 times
...
[Removed]
2 years, 1 month ago
C is the answer The best option for the penetration tester to maintain root-level persistence on this server during the test is to add a new user with ID 0 to the /etc/passwd file. This will allow the penetration tester to use the same user account as the other user, but with root privileges, meaning that it won’t disrupt the other user’s work. This can be done by adding a new line with the username and the numerical user ID 0 to the /etc/passwd file. For example, if the username for the other user is “johndoe”, the line to add would be “johndoe:x:0:0:John Doe:/root:/bin/bash”. After the user is added, the penetration tester can use the “su” command to switch to the new user and gain root privileges.
upvoted 3 times
...
[Removed]
2 years, 1 month ago
C is the answer ithink
upvoted 2 times
...
nickwen007
2 years, 2 months ago
A true TTY terminal is a type of terminal session that can be accessed over the network, allowing for remote access and complete control over a system. It enables users to make changes to the system, such as adding new users and modifying system files.
upvoted 4 times
[Removed]
2 years, 1 month ago
B is correct ?
upvoted 1 times
...
...
zimuz
2 years, 2 months ago
Selected Answer: B
chat gpt says b
upvoted 3 times
hakanay
1 year, 5 months ago
Use 4, not 3.5. It's C.
upvoted 1 times
...
...
kloug
2 years, 2 months ago
bbbbbbbb
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago