hardMultiple Choice
PT0-002 Cron job Practice Question
A penetration tester has gained a low-privileged shell on a Linux server. During enumeration, the tester finds a cron job that runs a script as root every five minutes. The script is located in /opt/backup.sh and is world-writable. Which technique should the tester use to escalate privileges?
⚠ Common exam trap
The trap here is that candidates may overthink and choose a kernel exploit or SUID attack, overlooking the simpler and more direct vector of modifying a world-writable script executed by a privileged cron job.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cron job script manipulation
The cron job runs as root and the script /opt/backup.sh is world-writable, meaning any user can modify it. By injecting a reverse shell or privilege escalation command into the script, the tester can execute arbitrary code with root privileges when the cron job triggers. This is a classic cron job script manipulation attack, leveraging the scheduled task's root execution context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kernel exploit
Why it's wrong here
A kernel exploit targets a vulnerability in the operating system kernel to gain root access, but the scenario already provides a world-writable root-owned cron script at /opt/backup.sh. The correct technique is to modify that script with a reverse shell or privilege-escalation command, which the cron daemon will execute as root within five minutes. A kernel exploit is tempting because it is a generic, powerful method for privilege escalation when no misconfigured file permissions or scheduled tasks exist, and would be correct if the cron job were not present or not modifiable.
- ✗
SUID binary exploitation
Why it's wrong here
Exploiting a misconfigured SUID binary is another method, but it may not be present; the cron script provides a direct, easy path.
- ✓
Cron job script manipulation
Why this is correct
Since the script is world-writable and run as root, the tester can insert a reverse shell or other commands to gain root access when the cron job fires.
- ✗
Password cracking
Why it's wrong here
Password cracking requires obtaining password hashes first; it is not directly applicable to this scenario.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Reverse shell
A reverse shell is a type of remote access attack where the target machine initiates an outbound connection back to the attacker, allowing the attacker to execute commands on the compromised system.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.