Courseiva
hardMultiple Choice

PT0-002 SUID bit Practice Question

A penetration tester has gained a low-privileged shell on a Linux server and discovers a binary with the SUID bit set owned by root. The binary executes a system command using a relative path without sanitizing user input. Which of the following techniques would the tester MOST likely use to escalate privileges?

⚠ Common exam trap

Candidates often think kernel exploitation (Option A) is always the go-to for privilege escalation, but the question specifically describes a misconfigured SUID binary with a relative path and unsanitized input, making PATH hijacking the most direct and likely technique.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the PATH environment variable to point to a malicious script with the same name as the command called by the binary

The SUID binary executes a system command using a relative path without sanitizing user input. By modifying the PATH environment variable to include a directory containing a malicious script with the same name as the command, the tester can cause the binary to execute the attacker-controlled script instead of the intended system command, thereby escalating privileges to root when the SUID binary runs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exploit a kernel vulnerability to gain root

    Why it's wrong here

    Exploiting a kernel vulnerability targets the operating system kernel itself, not the SUID binary that executes a system command via an unsanitised relative path. The scenario’s specific attack vector is a user-controlled command injection through the binary, which a kernel exploit does not address. This technique is tempting because kernel exploits are a common privilege-escalation method on outdated or unpatched systems, and would be correct if no exploitable SUID binary or misconfigured service were present.

  • ✓

    Modify the PATH environment variable to point to a malicious script with the same name as the command called by the binary

    Why this is correct

    PATH hijacking leverages the SUID binary's use of a relative path; by placing a malicious executable earlier in PATH, the binary executes it with root privileges.

  • ✗

    Impersonate the root user using sudo

    Why it's wrong here

    The tester is not in the sudoers file and does not have the root password, so sudo cannot be used.

  • ✗

    Preload a shared library using LD_PRELOAD

    Why it's wrong here

    LD_PRELOAD is not effective for SUID binaries as Linux systems disable it for security reasons.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.