mediumMultiple Choice
PT0-002 Practice Question: A penetration tester has gained a shell on a…
A penetration tester has gained a shell on a Linux machine as a low-privileged user. The user can execute the binary 'less' with sudo privileges without a password. Which technique can the tester use to escalate privileges to root?
⚠ Common exam trap
The trap here is that candidates may overlook the shell escape feature of pagers like 'less' and instead assume they need to exploit a binary vulnerability or use a generic 'sudo -u root bash' command, which fails because the sudoers rule is specific to 'less' only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the '!' command within 'less' to execute a shell.
The 'less' binary, when executed with sudo, retains its ability to spawn a shell via the '!' command. Since the user can run 'less' as root without a password, typing '!/bin/bash' (or simply '!bash') inside 'less' will execute a shell with root privileges, effectively escalating to root.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploit a buffer overflow in the 'less' binary.
Why it's wrong here
The sudoers entry grants command execution, not a memory-corruption primitive, so no buffer overflow is reachable through that path. It is tempting because binary exploitation is a classic escalation route, and would be correct if the binary were a vulnerable network service processing untrusted input.
- ✓
Use the '!' command within 'less' to execute a shell.
Why this is correct
Because 'less' runs as root via sudo without a password, its interactive '!' command spawns a shell inheriting root privileges. This satisfies the privilege-escalation constraint: GTFOBins-style abuse of a permitted binary, rather than exploiting a kernel or misconfigured file permission.
- ✗
Run 'sudo -u root bash' to switch to a root shell.
Why it's wrong here
Running 'sudo -u root bash' requires sudo rights to execute bash, which the sudoers entry does not grant; only 'less' is permitted. The technique that works is escaping less's interactive shell (!sh) to spawn root commands. Tempting because sudo -u root bash is the standard privilege-switch syntax when bash itself is authorised.
- ✗
Modify the PATH to trick sudo into running a malicious binary.
Why it's wrong here
sudo resolves the command via secure_path and validates the absolute binary path, so PATH manipulation does not redirect execution. It is tempting because PATH hijacking works for unqualified commands in scripts, and would be correct where a privileged process calls a binary without an absolute path.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.