PT0-002 Attacks and Exploits Practice Question
A tester is performing a privilege escalation on a Windows system and finds that the user has SeImpersonatePrivilege enabled. Which tool could be used to escalate to SYSTEM?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PrintSpoofer
SeImpersonatePrivilege can be exploited using tools like PrintSpoofer or Potato attacks to impersonate SYSTEM tokens.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PsExec
Why it's wrong here
PsExec is a Sysinternals utility for executing processes remotely via SMB and admin shares. It requires valid administrator credentials and network access, and it does not perform local privilege escalation by impersonating tokens. The SeImpersonatePrivilege technique used by tools like PrintSpoofer is irrelevant to PsExec's operation.
- ✓
PrintSpoofer
Why this is correct
PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege, a Windows privilege often held by service accounts. It leverages the Print Spooler service by creating a named pipe and tricking the spooler into connecting to it, allowing the attacker to impersonate a SYSTEM token. This enables command execution as SYSTEM without requiring remote credentials or network services.
- ✗
evil-winrm
Why it's wrong here
Evil-WinRM is a remote management shell that uses the WinRM protocol (port 5985/5986) to connect to Windows hosts over the network. It requires valid user credentials and a running WinRM service, and it is used for post-exploitation and remote administration rather than local privilege escalation. It does not interact with local token impersonation or SeImpersonatePrivilege in any way.
- ✗
pth-winexe
Why it's wrong here
pth-winexe is part of the pass-the-hash toolkit and allows remote command execution on Windows systems by authenticating with an NTLM hash via SMB. It is designed for lateral movement across a network with stolen credentials, not for escalating privileges on the local machine. The tool does not exploit token impersonation or leverage local privileges like SeImpersonatePrivilege to gain SYSTEM.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.