Courseiva
hardMultiple Choice

PT0-002 Cron job Practice Question

A penetration tester has gained a low-privileged shell on a Linux server. During enumeration, the tester finds a cron job that runs a script as root every five minutes. The script is located in /opt/backup.sh and is world-writable. Which technique should the tester use to escalate privileges?

⚠ Common exam trap

The trap here is that candidates may overthink and choose a kernel exploit or SUID attack, overlooking the simpler and more direct vector of modifying a world-writable script executed by a privileged cron job.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cron job script manipulation

The cron job runs as root and the script /opt/backup.sh is world-writable, meaning any user can modify it. By injecting a reverse shell or privilege escalation command into the script, the tester can execute arbitrary code with root privileges when the cron job triggers. This is a classic cron job script manipulation attack, leveraging the scheduled task's root execution context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kernel exploit

    Why it's wrong here

    A kernel exploit targets a vulnerability in the operating system kernel to gain root access, but the scenario already provides a world-writable root-owned cron script at /opt/backup.sh. The correct technique is to modify that script with a reverse shell or privilege-escalation command, which the cron daemon will execute as root within five minutes. A kernel exploit is tempting because it is a generic, powerful method for privilege escalation when no misconfigured file permissions or scheduled tasks exist, and would be correct if the cron job were not present or not modifiable.

  • ✗

    SUID binary exploitation

    Why it's wrong here

    Exploiting a misconfigured SUID binary is another method, but it may not be present; the cron script provides a direct, easy path.

  • ✓

    Cron job script manipulation

    Why this is correct

    Since the script is world-writable and run as root, the tester can insert a reverse shell or other commands to gain root access when the cron job fires.

  • ✗

    Password cracking

    Why it's wrong here

    Password cracking requires obtaining password hashes first; it is not directly applicable to this scenario.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.