Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

During a penetration test, the tester gains access to a web server and wants to escalate privileges to root. The tester discovers that the web application runs with a service account that has the SeImpersonatePrivilege enabled. Which attack is most likely to succeed for privilege escalation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JuicyPotato attack

SeImpersonatePrivilege allows a process to impersonate a user token. Tools like JuicyPotato exploit this privilege to impersonate SYSTEM by forcing a higher-privileged process to authenticate and then stealing its token. This is a common technique for local privilege escalation on Windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets the database layer through unsanitised queries, granting data access or command execution only where the DBMS permits it; it does not leverage SeImpersonatePrivilege to obtain a SYSTEM token. It is tempting because it is a common web-server initial foothold, but the privilege is already held.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash reuses captured NTLM hashes to authenticate as another user, which yields lateral movement rather than local escalation; SeImpersonatePrivilege enables token theft from a co-located privileged process. It is tempting because it escalates when an administrator hash is captured, but that is not this scenario.

  • ✗

    DLL hijacking

    Why it's wrong here

    DLL hijacking exploits unquoted service paths or missing DLLs loaded from writable directories, requiring such a flaw to exist; SeImpersonatePrivilege grants token impersonation instead. It is tempting because DLL search-order abuse reliably escalates when a privileged process loads a hijackable library, but no such condition is stated here.

  • ✓

    JuicyPotato attack

    Why this is correct

    JuicyPotato exploits the SeImpersonatePrivilege token by coercing a privileged service into authenticating, then impersonating its token via COM server abuse. Since the stem confirms the service account holds SeImpersonatePrivilege, this satisfies the exact prerequisite, enabling escalation to SYSTEM or root without needing kernel exploits.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.