exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 151 discussion

Actual exam question from CompTIA's PT0-001
Question #: 151
Topic #: 1
[All PT0-001 Questions]

During a penetration test, a tester identifies traditional antivirus running on the exploited server. Which of the following techniques would BEST ensure persistence in a post-exploitation phase?

  • A. Shell binary placed in C:\windows\temp
  • B. Modified daemons
  • C. New user creation
  • D. Backdoored executables
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
versun
Highly Voted 3 years, 11 months ago
I think answer is C
upvoted 6 times
...
smalltech
Highly Voted 3 years, 11 months ago
B. Testers who are able to inject their programs into the configuration of existing daemons or who are able to establish their own daemons for backdoors, C2s, or other techniques of attack can establish long-term persistence, regardless of the logged-in users. (Guessing that this is a linux server) For windows - Daemons can be used for persistence and privilege escalation in Linux, but be sure to look at the Windows equivalent: scheduled tasks. CompTIA Pentest + passport book
upvoted 5 times
eroms
3 years, 11 months ago
The equivalent of Daemon is not Scheduled tasks but Services.
upvoted 5 times
...
dumdada
3 years, 7 months ago
The only option the antivirus won't detect is the user creation.
upvoted 1 times
...
...
miabe
Most Recent 2 years, 10 months ago
Selected Answer: C
looks good to me
upvoted 1 times
...
Jetlife
3 years, 1 month ago
Im going with B
upvoted 1 times
...
MrRiver
3 years, 8 months ago
Would go with C. New User Creation is listed as persitance mechanism according to Comptia. A. just a shell binary does nothing D.) also a backdoored exe does not help is it is not run ... b.) Modifying a demon may get noticed by the antivirus. but c: won't be detected by a classic AV
upvoted 3 times
...
carlo479
3 years, 10 months ago
the answer is B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...