Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester needs to escalate privileges on a Linux system and finds that the user can run a script with sudo that has a vulnerable argument. Which resource should the tester consult to find exploitation techniques for common sudo misconfigurations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GTFOBins

GTFOBins is a curated list of Unix binaries that can be exploited to bypass local security restrictions, including sudo misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    GTFOBins

    Why this is correct

    GTFOBins is a curated repository of Unix binary exploitation techniques, specifically cataloging ways to abuse binaries for privilege escalation. For a Linux system, if a penetration tester discovers via 'sudo -l' that a binary can be executed with sudo privileges, GTFOBins provides exact command sequences to leverage that binary to spawn a root shell or read protected files. It is the go-to, command-focused resource for sudo misconfigurations and setuid abuse, making it directly applicable to the scenario.

  • ✗

    Exploit-DB

    Why it's wrong here

    Exploit-DB is a public database of exploits, shellcodes, and proof-of-concepts covering a wide range of software vulnerabilities, but it is not designed as a privilege escalation command reference. While one might find an exploit for a specific vulnerable service or kernel, it does not systematically list abusable Unix binaries or provide concise techniques for misconfigured sudo entries. Its utility is in searching for known CVEs, not in enumerating the many ways a particular binary can be turned into a root shell.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is a comprehensive exploitation framework containing modules for scanning, exploiting, and post-exploitation, but it is a heavyweight tool that requires an active session or a target to run against. It does not serve as a quick, command-level reference for abusing sudo misconfigurations; even if a relevant module exists, the tester must often manually craft the technique or use GTFOBins to understand the underlying binary behavior. In this scenario, GTFOBins is lighter and more precise because it directly lists the fork/exec/read techniques for each binary.

  • ✗

    CVE Details

    Why it's wrong here

    CVE Details is a vulnerability statistics and severity database that aggregates CVE entries with CVSS scores, affected products, and patch information. It does not contain exploitation techniques or instructions on how to chain a vulnerability into a privilege escalation path, especially for sudo misconfigurations. While it can help identify known vulnerable versions, it lacks the actionable, binary-specific 'how-to' guidance that GTFOBins provides for escalating privileges on a Linux host.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.