Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester has gained a low-privilege shell on a Windows server and discovers the user has the SeImpersonatePrivilege. Which tool could the tester use to escalate privileges to SYSTEM?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

PrintSpoofer exploits SeImpersonatePrivilege to escalate privileges on Windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mimikatz

    Why it's wrong here

    Mimikatz is a credential-dumping tool that extracts cleartext passwords, hashes, and Kerberos tickets from LSASS memory on a compromised host. It does not perform token impersonation or directly abuse SeImpersonatePrivilege, and it lacks the named-pipe server logic required to force a privileged process to authenticate and yield a SYSTEM token. Therefore, although Mimikatz is essential for credential harvesting, it would not be the tool to exploit the SeImpersonatePrivilege described in the scenario.

  • ✗

    SharpHound

    Why it's wrong here

    SharpHound is the data collection component of BloodHound that maps Active Directory relationships such as user sessions, group memberships, trust paths, and routes to Domain Admin rights. It runs from a foothold but focuses on domain-wide attack paths rather than local privilege escalation on the immediate compromised system. While it might reveal domain-admin paths reachable later, it cannot directly turn SeImpersonatePrivilege into a local SYSTEM shell on the current host.

  • ✗

    PowerUp

    Why it's wrong here

    PowerUp is a PowerShell reconnaissance script that audits a Windows host for common privilege escalation vectors, such as vulnerable service permissions, unquoted service paths, writable binaries, and always-install-elevated policies. One of its checks may report that the current process carries SeImpersonatePrivilege, but PowerUp does not include an actual token impersonation exploit for that specific finding. It would simply flag the privilege and prompt the tester to use a dedicated tool like PrintSpoofer, so it is useful for detection but not the direct exploit in this scenario.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer is a token impersonation exploit that specifically leverages SeImpersonatePrivilege by creating a malicious named pipe server and then coercing a privileged process—commonly the Print Spooler service—to connect to it. The tool captures the resulting SYSTEM token and uses ImpersonateNamedPipeClient to execute a command with elevated privileges, giving the attacker a SYSTEM shell. It is designed as a modern replacement for JuicyPotato, working reliably on fully patched Windows 10 and Server 2019 builds where older Potato exploits often fail, making it the correct choice.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.