Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester has gained a low-privilege shell on a Windows server and discovered that the SeImpersonatePrivilege is enabled. Which of the following tools would be most appropriate to escalate privileges to SYSTEM-level access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

SeImpersonatePrivilege allows token impersonation. Tools like PrintSpoofer exploit this to gain SYSTEM privileges. Potato attacks (JuicyPotato) also work, but PrintSpoofer is more modern and reliable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pth-winexe

    Why it's wrong here

    pth-winexe is a pass-the-hash tool from the Samba suite that authenticates to remote Windows hosts using NTLM hashes to execute commands, making it suitable for lateral movement or remote administration. It does not perform local privilege escalation because it requires existing credentials or hashes for a privileged account rather than exploiting a vulnerability or misconfiguration on the current host. Even if a hash is available, that is an authentication attack, not a privilege escalation technique.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer is a local privilege escalation tool that abuses the SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege commonly granted to Windows service accounts. It leverages the Print Spooler service's named pipe to capture a SYSTEM token and then impersonates it, spawning a process as NT AUTHORITY\SYSTEM. This directly escalates the existing low-privilege shell to full system privileges on the same host, making it the correct choice for this scenario.

  • ✗

    Responder

    Why it's wrong here

    Responder is a network poisoning tool that listens for LLMNR, NBT-NS, and mDNS broadcasts and responds to them to capture NTLMv2 hashes or credentials from other machines. It is used in the discovery or exploitation phase to gain initial access, not to escalate privileges on an already compromised local host. Its effectiveness depends on other systems generating broadcast traffic, so it has no role in escalating a low-privilege shell on the current machine.

  • ✗

    CrackMapExec

    Why it's wrong here

    CrackMapExec is a post-exploitation framework that automates lateral movement by running commands across many hosts via SMB, WinRM, or LDAP using harvested credentials or hashes. It assumes you already have sufficient privileges or credentials to authenticate to remote systems, and it does not exploit local privilege escalation vectors. From a low-privilege shell on a single host, CrackMapExec cannot raise your privileges because it lacks any mechanism to elevate the current process or token.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.