Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

During a Linux privilege escalation attempt, a tester checks for misconfigurations that could allow running commands as root. Which of the following are potential vectors? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sudo misconfigurations

SUID/SGID binaries, sudo misconfigurations, and writable cron scripts are common escalation vectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unquoted service paths

    Why it's wrong here

    Unquoted service paths are a Windows-specific vulnerability that arises when the Windows Service Control Manager interprets spaces in a service binary path. On a Linux system, services are managed by systemd unit files, init scripts, or other Unix mechanisms, none of which split a path into ambiguous components. Even if a Linux executable path contains spaces, the kernel does not parse it in that way, so this option is not a valid Linux privilege escalation vector.

  • ✓

    Sudo misconfigurations

    Why this is correct

    Sudo misconfigurations are a critical Linux privilege escalation vector because a user's sudo rights may allow running a command that can be leveraged to obtain a root shell, such as `sudo vim` or `sudo python -c 'import pty; pty.spawn("/bin/bash")'`. Misconfigurations include NOPASSWD entries, unsafe wildcard rules, or binary paths that can be replaced, and they directly expose unintended root-level execution. An attacker enumerates `sudo -l` to find such permissive entries.

  • ✓

    Writable scripts in cron jobs

    Why this is correct

    Writable scripts in cron jobs allow privilege escalation when a scheduled job references a file or script that the current user can modify, because the script will execute with the cron job's privileges, often root. An attacker can backdoor the script by appending arbitrary commands or replacing it entirely, and then wait for the cron trigger. This is a common Linux misconfiguration that can be discovered by inspecting `/etc/crontab`, `/etc/cron.*/`, and user crontabs, and then checking file permissions.

  • ✗

    DLL hijacking

    Why it's wrong here

    DLL hijacking is a Windows attack technique that exploits dynamic-link library search order to load a malicious DLL, but Linux does not use DLLs; it uses shared libraries (`.so` files) loaded by the dynamic linker. While Linux has analogous concepts like `LD_PRELOAD` or `LD_LIBRARY_PATH` hijacking, the specific 'DLL hijacking' term and the characteristic Windows registry/application DLL loading mechanism is not applicable. In a Linux privilege escalation attempt, this option would be discarded as irrelevant.

  • ✓

    SUID/SGID binaries

    Why this is correct

    SUID/SGID binaries are a standard Linux privilege escalation vector because a binary with the SUID bit set runs with the file owner's effective UID, often root, regardless of who launches it. Attackers hunt for these with `find / -perm -4000 -type f 2>/dev/null` and exploit known binaries or custom misconfigured programs to execute commands as root. The SGID bit similarly inherits group ownership, which can be dangerous if the group grants write access to sensitive resources.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.