PT0-002 Attacks and Exploits Practice Question
A tester is exploiting a Linux system and finds a binary with the SUID bit set owned by root. The binary executes other commands. Which technique would allow privilege escalation to root?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PATH manipulation
If a SUID binary executes commands (e.g., via system() or exec()), it may be exploited to run arbitrary commands as root, especially if the path is not absolute.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLL hijacking
Why it's wrong here
DLL hijacking is a Windows-specific exploitation vector that abuses the DLL search order to load a malicious library in place of a legitimate one. Since the target is a Linux system running an ELF binary, there are no DLLs; Linux uses shared objects (.so) and the dynamic linker with mechanisms like LD_PRELOAD. Even if an equivalent shared-object attack existed, it would not be called DLL hijacking, and the scenario provides no evidence of such a component. Therefore, this option is incorrect for a Linux SUID binary.
- ✗
Kernel exploit
Why it's wrong here
A kernel exploit targets a specific vulnerability in the operating system kernel, such as a race condition or missing permission check, to elevate privileges. In this scenario, the only disclosed detail is a SUID binary; there is no indication of an unpatched kernel, vulnerable module, or relevant CVE. Choosing a kernel exploit would require reconnaissance to confirm a kernel flaw, which the question does not provide. Thus, this is not the correct technique for the described situation.
- ✗
Token impersonation
Why it's wrong here
Token impersonation is a Windows-only privilege escalation technique that leverages access tokens, particularly the SeImpersonatePrivilege, to assume the identity of another user (often SYSTEM). Linux security is based on Unix user IDs, group IDs, and capabilities, not on Windows tokens, so this technique has no direct equivalent in a Linux environment. The presence of a SUID binary does not create any token-based attack surface. Consequently, token impersonation is not a valid answer for a Linux system.
- ✓
PATH manipulation
Why this is correct
When a SUID binary executes an external command using a relative path, such as calling system('ls') or execvp('ls', ...), it relies on the PATH environment variable set by the invoking user. An attacker can prepend a custom directory to PATH containing a malicious executable with the name of the expected command; since the SUID binary runs with root privileges, the malicious executable executes with root privileges, granting privilege escalation. The exploit succeeds only if the binary does not sanitize the environment (e.g., via secure_getenv) and uses a relative path instead of an absolute path. This is precisely the described scenario, making PATH manipulation the correct answer.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.