PT0-002 Attacks and Exploits Practice Question
A tester has exploited a Linux system and gained a low-privilege shell. The tester runs 'sudo -l' and sees that the current user can run /usr/bin/find as root without a password. Which privilege escalation technique should the tester use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GTFOBins technique for find
The find command can be used to execute other commands via its -exec parameter, allowing privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SUID binary exploitation
Why it's wrong here
The privilege escalation vector here is a sudoers entry granting the user the right to run `find` as root, not a file with the setuid bit. SUID exploitation targets binaries that execute with the owner's privileges due to the `setuid` permission, such as a writable script or a vulnerable binary like `passwd`. Since the scenario explicitly describes a sudo rule, labeling it as SUID misidentifies the underlying mechanism, even though both can yield root access.
- ✗
PATH manipulation
Why it's wrong here
PATH manipulation involves altering the `PATH` environment variable to trick a program into executing a malicious binary of the same name as a legitimate command, often when sudo uses a relative path or lacks `secure_path`. In this scenario, the sudo rule specifies an absolute path to `find` (e.g., `/usr/bin/find`) and sudo's `secure_path` prevents environment-based hijacking. The tester directly abuses `find`'s `-exec` capability under sudo, not by replacing an executable in the search path.
- ✗
Kernel exploit
Why it's wrong here
Kernel exploits target vulnerabilities in the operating system's core code to gain elevated permissions, whereas this scenario provides a misconfigured SUID-like capability via sudo privileges. A kernel exploit would be the correct technique if the tester needed to bypass security controls by leveraging an unpatched flaw in the OS version itself rather than exploiting existing permission settings like the 'find' command.
- ✓
GTFOBins technique for find
Why this is correct
This is a classic GTFOBins technique: when `sudo` permits a user to run `find` as root, the `-exec` or `-execdir` actions can execute arbitrary commands with elevated privileges. For example, `sudo find . -exec /bin/sh \;` spawns a root shell because `find` runs as root under sudo. GTFOBins enumerates such built-in command-execution mechanisms for common binaries, making this the correct method to escalate from the low-privileged user.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.