PT0-002 Attacks and Exploits Practice Question
A penetration tester has gained initial access to an internal Windows server and wants to escalate privileges to SYSTEM. The tester identified that the current user has the SeImpersonatePrivilege enabled. Which TWO of the following tools or techniques would be most appropriate to exploit this privilege for privilege escalation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PrintSpoofer
Option A, PrintSpoofer, is correct because it abuses the SeImpersonatePrivilege by coercing the Print Spooler service into authenticating to a controlled named pipe, then impersonating the resulting SYSTEM token to gain elevated privileges. Option B, Potato attacks such as JuicyPotato, is correct because these techniques also leverage SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) by tricking a privileged service into connecting to an attacker-controlled COM server or named pipe, allowing token impersonation to SYSTEM. Option C, PsExec, is not appropriate here because it is a remote execution/lateral movement tool that requires administrative credentials or SMB access, not a local SeImpersonatePrivilege escalation technique. Option D, Pass-the-Hash, is incorrect because it uses captured NTLM hashes for authentication to other systems and does not exploit SeImpersonatePrivilege. Option E, Kerberoasting, is incorrect because it targets service accounts with SPNs to crack their passwords offline and is unrelated to token impersonation privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PrintSpoofer
Why this is correct
PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege by creating a malicious named pipe and tricking the Print Spooler service into connecting to it, forcing a SYSTEM token to be impersonated. Unlike JuicyPotato, it relies on the printer spooler rather than COM objects, and it works on modern Windows versions (Windows 10/Server 2016+) where older Potato variants are mitigated. This makes it a direct, reliable method to escalate from an impersonating service account to SYSTEM.
- ✓
Potato attacks (e.g., JuicyPotato)
Why this is correct
Potato attacks, such as JuicyPotato, exploit SeImpersonatePrivilege by abusing Windows COM objects (e.g., BITS) to trigger NTLM authentication from a service running as SYSTEM to an attacker-controlled mock server. The captured SYSTEM token is then impersonated to run arbitrary commands with elevated privileges. These attacks were highly effective on Windows Server 2012/2016 but rely on deprecated COM interfaces, making them largely patched or mitigated on Windows 10 1809 and Server 2019 and later.
- ✗
PsExec
Why it's wrong here
PsExec is a Sysinternals tool for remote execution and lateral movement, not a privilege escalation technique. It operates by uploading a service binary to the ADMIN$ share of a remote host and starting it via SMB, requiring valid administrative credentials; it does not interact with SeImpersonatePrivilege or token impersonation. Even if PsExec is used to run a process with SYSTEM privileges, the privilege escalation itself must already be achieved by other means, so it is not a candidate for exploiting the impersonation privilege.
- ✗
Pass-the-Hash
Why it's wrong here
Pass-the-Hash is a lateral movement technique that uses a captured NTLM hash to authenticate against remote systems without knowing the plaintext password, but it does not escalate privileges on the current host. The attacker reuses an existing user's hash to impersonate that user across the network, whereas the question's scenario requires local privilege escalation via SeImpersonatePrivilege. It is orthogonal to token impersonation and does not grant SYSTEM privileges on the compromised machine.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting targets Kerberos service accounts by extracting TGS tickets (via SPN requests) and subjecting them to offline brute-force or dictionary attacks to recover plaintext service account credentials. It is a credential theft and offline cracking technique, not a local privilege escalation method, and it does not involve SeImpersonatePrivilege or process token impersonation. While it may yield credentials usable for further access, it does not directly exploit impersonation privileges on an already compromised host.
Go deeper
Related to this question
Learn chapter
Insecure Deserialization Attacks
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Kerberoasting
Kerberoasting is an attack where a hacker steals service account password hashes from Active Directory to crack them offline and gain unauthorized access.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.