PT0-002 Attacks and Exploits Practice Question
A tester has gained a low-privilege shell on a Windows machine and found that the user has the SeImpersonatePrivilege enabled. Which attack can be used to escalate privileges to SYSTEM?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Token impersonation using PrintSpoofer
SeImpersonatePrivilege allows impersonating a client after authentication; tools like PrintSpoofer, RoguePotato exploit this to gain SYSTEM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLL hijacking
Why it's wrong here
DLL hijacking is a code execution technique that places a malicious DLL in a directory an application searches before its legitimate system path, causing the application to load the attacker's code. For this to succeed, the attacker must have write access to that directory, but on modern Windows, system directories are protected and a low-privilege shell rarely has the necessary permissions. Even when DLL hijacking works, it typically only grants the privileges of the vulnerable application, which is often not SYSTEM, making it an unreliable path to full administrative control. Therefore, DLL hijacking is not the correct privilege escalation method here.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting is an Active Directory attack that targets service accounts by requesting Ticket-Granting Service (TGS) tickets for Service Principal Names (SPNs) and then cracking the encrypted ticket data offline to recover the password. This technique does not directly escalate privileges on the local Windows host; instead, it yields a domain service account credential that may or may not have local administrative rights, and it requires time and successful password cracking. Since the tester is operating from a low-privilege shell on a single Windows machine, Kerberoasting is not a plausible next step unless the machine is domain-joined and the attacker can request tickets, but it does not provide immediate SYSTEM access.
- ✓
Token impersonation using PrintSpoofer
Why this is correct
Token impersonation using PrintSpoofer is a powerful privilege escalation technique that exploits the Print Spooler service's named pipe to manipulate an impersonation token and execute commands with SYSTEM privileges. The tool leverages the SeImpersonatePrivilege, which is typically granted to service accounts (e.g., IIS, MSSQL) but is not normally enabled for standard low-privilege users; however, when the current process holds this privilege, PrintSpoofer can request a token from the Spooler that represents the SYSTEM account and then impersonate it. This method does not require write access to system directories, domain credentials, or specific Group Policy settings, making it a direct and reliable path to SYSTEM escalation in this scenario, hence the correct answer.
- ✗
AlwaysInstallElevated
Why it's wrong here
AlwaysInstallElevated is a privilege escalation technique that relies on a specific Windows Installer policy where the AlwaysInstallElevated registry keys are configured for both the computer and the current user, allowing any user to install MSI packages with SYSTEM privileges. This misconfiguration is relatively rare in hardened environments; if the policy is not enabled, the technique fails immediately because the user cannot override the default install permissions. Even when enabled, the attacker must craft or run an MSI file, and the escalation depends on the presence of specific registry values, which is not assumed from a low-privilege shell, so it is not the correct choice.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.