Enumerate sudo -l, SUID/SGID files, cron jobs, writable paths, and kernel version, then exploit the simplest misconfiguration to gain root. The key is verifying the exact command context and permissions before acting so the escalation is reliable and does not destabilize the host.
Start practicing
Linux Privilege Escalation — choose a session length
Free · No account required
Domain overview
Linux Privilege Escalation on PEN-200 covers moving from a low-privileged shell to root by abusing misconfigurations rather than exploits alone. You enumerate sudo rights, SUID/SGID binaries, cron jobs, writable files, capabilities, and kernel versions, then pick the least disruptive path and prove root access with a reliable, repeatable exploit.
Exam objectives
Reading sudo -l output and abusing NOPASSWD entries, wildcards, and GTFOBins-style command escapes
Finding SUID/SGID binaries and exploiting relative path or PATH hijacking in system() calls
Enumerating root cron jobs and writable scripts or directories they execute
Identifying kernel and service versions, then selecting a matching local privilege escalation exploit
Running a kernel exploit first instead of checking sudo, SUID, and cron misconfigurations that are safer and more reliable
Missing that a SUID binary calls a command without an absolute path, so PATH hijacking is possible
Editing a root cron script without preserving permissions or triggering the job, or breaking the target so it crashes
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?
2Refer to the exhibit. Given the sudo privileges, which command will successfully spawn a root shell?
3Which Linux kernel feature, if misconfigured or outdated, allows an unprivileged user to gain root access by exploiting a vulnerability in the handling of user namespaces?
4Refer to the exhibit. The 'find' binary has the SUID bit set. How can you leverage this to gain a root shell?
5You find that a binary relies on a relative path to execute a secondary script. If you cannot modify the PATH variable, what is the best alternative to exploit this configuration?
6When reviewing 'sudo -l' output, what does the 'NOPASSWD' tag signify for the listed command?
7When performing a kernel exploit for privilege escalation, what is the most significant risk to the stability of the target system?
8Why is it often effective to check for 'Capabilities' on Linux binaries when SUID is not present?
9Which file is essential for auditing to determine which users have been granted sudo privileges?
10Which command is most useful for identifying processes that are running as root, which might be potential targets for privilege escalation?
11You identify a cron job running as root that executes a script located in a writable directory. What is the most reliable way to escalate privileges in this scenario?
12During a Linux privilege escalation assessment, you discover that the current user can run `/usr/bin/find` via sudo without a password. You execute `sudo find /home -exec /bin/bash \;`. What is the outcome?
13You have a low-privileged shell on a Linux host. You discover a cron job that runs every minute as root and executes a script located at /opt/backup/backup.sh. The script is world-writable. However, you also notice that the directory /opt/backup is owned by root and has permissions 755. Which of the following is the MOST reliable way to escalate privileges?
14You have obtained a low-privileged shell on a Linux server. During enumeration, you discover a file named `backup.sh` in `/opt/scripts` that is owned by root and has permissions `-rwxr-xr-x`. A cron job runs this script every night as root. The directory `/opt/scripts` has permissions `drwxrwxr-x` and is owned by root:developers. Your user is a member of the `developers` group. What is the most reliable way to escalate privileges?
15While enumerating a Linux host, you notice that the `passwd` command has the SUID bit set and is owned by root. You recall that SUID binaries run with the privileges of the file owner. Which of the following is the most direct way to leverage this to gain root access?
16During post-exploitation on a Linux target, you discover a binary with the SUID bit set owned by root. Running 'strings' on the binary reveals it calls 'system("ps")' without specifying an absolute path. Which of the following techniques is most likely to allow you to escalate privileges by exploiting this behavior?
17A penetration tester discovers that the current user can write to a script located in /opt/backup/ that is executed every minute by a cron job running as root. The script has permissions `-rwxr-xr-x 1 root root`. What is the MOST reliable way to escalate privileges?
18During a Linux privilege escalation assessment, you obtain a low-privileged shell as user 'student'. You run 'id' and see the user belongs to the 'docker' group. Which command will most reliably escalate to root on this host?
Enumerate sudo -l, SUID/SGID files, cron jobs, writable paths, and kernel version, then exploit the simplest misconfiguration to gain root. The key is verifying the exact command context and permissions before acting so the escalation is reliable and does not destabilize the host.
The Courseiva PEN-200 question bank contains 18 questions in the Linux Privilege Escalation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Linux Privilege Escalation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included