Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

After compromising a Linux host, you want to escalate privileges by exploiting a cron job that runs a script with root privileges. The script references an executable using a relative path. Which attack technique is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PATH manipulation

PATH manipulation works by modifying the PATH environment variable so that when the script calls the executable (by name only, no full path), the attacker's malicious version runs with the privileges of the script.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PATH manipulation

    Why this is correct

    PATH manipulation is the correct privilege escalation vector in this scenario because cron jobs often run with a minimal PATH such as /usr/bin:/bin. If a scheduled task invokes a command without an absolute path (e.g., 'tar' instead of '/usr/bin/tar'), an attacker who can place a malicious executable named 'tar' in any directory that appears earlier in the resolved search order—for instance, a world-writable directory like /tmp—can hijack execution. The cron daemon then executes the attacker's binary with the target user's privileges, enabling arbitrary command execution and potential root compromise if the job runs as root.

  • ✗

    SUID binary exploitation

    Why it's wrong here

    SUID binary exploitation involves taking advantage of executables that have the setuid bit set, causing them to run with the file owner's permissions, often root. While chaining a vulnerable SUID binary can lead to privilege escalation, this attack vector is distinct from cron job PATH misconfiguration: it requires locating a specific binary with a known vulnerability or misconfiguration, not manipulating the environment PATH. In the given scenario where a scheduled job relies on relative paths, exploiting SUID binaries would not address the underlying weakness in the cron task.

  • ✗

    Kernel exploit

    Why it's wrong here

    Kernel exploits target vulnerabilities in the Linux kernel itself, such as use-after-free or race conditions, to gain elevated privileges. They are system-level attacks that depend on the exact kernel version and patch level, and they are unrelated to how scheduled tasks resolve executable paths. In this case, the attack surface is the cron job's environment and relative path usage, not the kernel's internals, so attempting a kernel exploit would be a different and inappropriate technique for the described misconfiguration.

  • ✗

    DLL hijacking

    Why it's wrong here

    DLL hijacking is a Windows-based attack technique that involves planting a malicious DLL file in a location where a legitimate application will load it due to the application's DLL search order. Linux does not use DLLs; instead, it uses shared object (.so) files, and analogous attacks would leverage LD_PRELOAD or RPATH vulnerabilities. Since the scenario involves cron job PATH manipulation on a Linux host, DLL hijacking is not applicable and does not provide a valid privilege escalation path in this context.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.