Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester has gained initial access to an internal Windows server and wants to escalate privileges to SYSTEM. The tester identified that the current user has the SeImpersonatePrivilege enabled. Which TWO of the following tools or techniques would be most appropriate to exploit this privilege for privilege escalation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

Option A, PrintSpoofer, is correct because it abuses the SeImpersonatePrivilege by coercing the Print Spooler service into authenticating to a controlled named pipe, then impersonating the resulting SYSTEM token to gain elevated privileges. Option B, Potato attacks such as JuicyPotato, is correct because these techniques also leverage SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) by tricking a privileged service into connecting to an attacker-controlled COM server or named pipe, allowing token impersonation to SYSTEM. Option C, PsExec, is not appropriate here because it is a remote execution/lateral movement tool that requires administrative credentials or SMB access, not a local SeImpersonatePrivilege escalation technique. Option D, Pass-the-Hash, is incorrect because it uses captured NTLM hashes for authentication to other systems and does not exploit SeImpersonatePrivilege. Option E, Kerberoasting, is incorrect because it targets service accounts with SPNs to crack their passwords offline and is unrelated to token impersonation privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege by creating a malicious named pipe and tricking the Print Spooler service into connecting to it, forcing a SYSTEM token to be impersonated. Unlike JuicyPotato, it relies on the printer spooler rather than COM objects, and it works on modern Windows versions (Windows 10/Server 2016+) where older Potato variants are mitigated. This makes it a direct, reliable method to escalate from an impersonating service account to SYSTEM.

  • ✓

    Potato attacks (e.g., JuicyPotato)

    Why this is correct

    Potato attacks, such as JuicyPotato, exploit SeImpersonatePrivilege by abusing Windows COM objects (e.g., BITS) to trigger NTLM authentication from a service running as SYSTEM to an attacker-controlled mock server. The captured SYSTEM token is then impersonated to run arbitrary commands with elevated privileges. These attacks were highly effective on Windows Server 2012/2016 but rely on deprecated COM interfaces, making them largely patched or mitigated on Windows 10 1809 and Server 2019 and later.

  • ✗

    PsExec

    Why it's wrong here

    PsExec is a Sysinternals tool for remote execution and lateral movement, not a privilege escalation technique. It operates by uploading a service binary to the ADMIN$ share of a remote host and starting it via SMB, requiring valid administrative credentials; it does not interact with SeImpersonatePrivilege or token impersonation. Even if PsExec is used to run a process with SYSTEM privileges, the privilege escalation itself must already be achieved by other means, so it is not a candidate for exploiting the impersonation privilege.

  • ✗

    Pass-the-Hash

    Why it's wrong here

    Pass-the-Hash is a lateral movement technique that uses a captured NTLM hash to authenticate against remote systems without knowing the plaintext password, but it does not escalate privileges on the current host. The attacker reuses an existing user's hash to impersonate that user across the network, whereas the question's scenario requires local privilege escalation via SeImpersonatePrivilege. It is orthogonal to token impersonation and does not grant SYSTEM privileges on the compromised machine.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting targets Kerberos service accounts by extracting TGS tickets (via SPN requests) and subjecting them to offline brute-force or dictionary attacks to recover plaintext service account credentials. It is a credential theft and offline cracking technique, not a local privilege escalation method, and it does not involve SeImpersonatePrivilege or process token impersonation. While it may yield credentials usable for further access, it does not directly exploit impersonation privileges on an already compromised host.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.