PT0-002 Attacks and Exploits Practice Question
During a Linux privilege escalation attempt, a tester checks for misconfigurations that could allow running commands as root. Which of the following are potential vectors? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sudo misconfigurations
SUID/SGID binaries, sudo misconfigurations, and writable cron scripts are common escalation vectors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unquoted service paths
Why it's wrong here
Unquoted service paths are a Windows-specific vulnerability that arises when the Windows Service Control Manager interprets spaces in a service binary path. On a Linux system, services are managed by systemd unit files, init scripts, or other Unix mechanisms, none of which split a path into ambiguous components. Even if a Linux executable path contains spaces, the kernel does not parse it in that way, so this option is not a valid Linux privilege escalation vector.
- ✓
Sudo misconfigurations
Why this is correct
Sudo misconfigurations are a critical Linux privilege escalation vector because a user's sudo rights may allow running a command that can be leveraged to obtain a root shell, such as `sudo vim` or `sudo python -c 'import pty; pty.spawn("/bin/bash")'`. Misconfigurations include NOPASSWD entries, unsafe wildcard rules, or binary paths that can be replaced, and they directly expose unintended root-level execution. An attacker enumerates `sudo -l` to find such permissive entries.
- ✓
Writable scripts in cron jobs
Why this is correct
Writable scripts in cron jobs allow privilege escalation when a scheduled job references a file or script that the current user can modify, because the script will execute with the cron job's privileges, often root. An attacker can backdoor the script by appending arbitrary commands or replacing it entirely, and then wait for the cron trigger. This is a common Linux misconfiguration that can be discovered by inspecting `/etc/crontab`, `/etc/cron.*/`, and user crontabs, and then checking file permissions.
- ✗
DLL hijacking
Why it's wrong here
DLL hijacking is a Windows attack technique that exploits dynamic-link library search order to load a malicious DLL, but Linux does not use DLLs; it uses shared libraries (`.so` files) loaded by the dynamic linker. While Linux has analogous concepts like `LD_PRELOAD` or `LD_LIBRARY_PATH` hijacking, the specific 'DLL hijacking' term and the characteristic Windows registry/application DLL loading mechanism is not applicable. In a Linux privilege escalation attempt, this option would be discarded as irrelevant.
- ✓
SUID/SGID binaries
Why this is correct
SUID/SGID binaries are a standard Linux privilege escalation vector because a binary with the SUID bit set runs with the file owner's effective UID, often root, regardless of who launches it. Attackers hunt for these with `find / -perm -4000 -type f 2>/dev/null` and exploit known binaries or custom misconfigured programs to execute commands as root. The SGID bit similarly inherits group ownership, which can be dangerous if the group grants write access to sensitive resources.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.