Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester has gained a low-privileged…

A penetration tester has gained a low-privileged shell on a Linux server. During enumeration, the tester discovers a binary with the SUID bit set that belongs to root and is known to have a buffer overflow vulnerability. What is the MOST effective next step to escalate privileges?

⚠ Common exam trap

Many exam-takers confuse SUID with sudo, assuming sudo can be used to run the binary as root, but SUID binaries execute with the owner's privileges automatically without requiring sudoers configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Develop and execute a buffer overflow exploit against the binary to gain a root shell

The SUID binary owned by root and vulnerable to a buffer overflow allows a low-privileged user to execute it with root privileges. Developing and executing a buffer overflow exploit against the binary will overwrite the return address or function pointer to spawn a root shell, directly escalating privileges to root. This is the most effective method because it leverages the existing vulnerability to gain full control without relying on other misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the binary to execute a command that changes the root password

    Why it's wrong here

    Attempting to use the SUID binary to change the root password is not only unreliable but also destructive. A SUID binary merely executes with the file owner's privileges, and it only does what its own code says; unless it has an explicit command-injection flaw or a hidden option to run arbitrary commands, it cannot accept a 'change password' instruction. Even if it somehow could, altering the root password would break access for legitimate admins, potentially locking out yourself if you lack interactive root, and it creates tremendous noise that will tip off defenders.

  • ✓

    Develop and execute a buffer overflow exploit against the binary to gain a root shell

    Why this is correct

    The correct approach is to exploit a vulnerability in the SUID binary itself. Because the binary's effective UID is root, a successful buffer overflow exploit that hijacks control flow can execute shellcode with privileges equivalent to root. The shellcode should typically set real/effective/saved UID to 0 and then spawn a shell, yielding an interactive root session without altering any system state or requiring credentials.

  • ✗

    Modify the binary's permissions to allow execution by any user

    Why it's wrong here

    Changing the file's permission bits does not confer privilege escalation. The binary is already executable by all users as a SUID program, and a standard non-root user does not have write access to modify a root-owned file to add permissions for themselves. Even if you could chmod it, making it more permissive grants no extra privilege; the only relevant bit is the setuid bit, which is already present, and modifying permissions could inadvertently clear that bit.

  • ✗

    Use sudo to run the binary as root

    Why it's wrong here

    Using sudo to execute the binary as root is a dead end because the penetration tester does not have sudo rights for that binary. The sudo binary consults /etc/sudoers and requires an explicit rule permitting the current user to run the command; without such a rule, and without a known sudo password, sudo will refuse the operation and may log the attempted authorization failure. The presence of a SUID bit is irrelevant to sudo's configuration, and sudo does not bypass existing restrictions.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.