Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 SUID bit Practice Question

During a Linux privilege escalation attempt, a tester finds a binary with the SUID bit set that is not on the GTFOBins list. The binary executes /bin/bash with the effective UID of root. What is the most likely way to exploit this?

⚠ Common exam trap

The -p flag is required to prevent bash from dropping the elevated privileges. Without it, the shell reverts to the real UID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the binary with the -p flag

When an SUID binary executes /bin/bash, bash will drop the effective UID unless the -p (privileged) flag is used. Running the binary with '-p' preserves the effective UID, granting a root shell. Simply running the binary may result in a shell with the original user's privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use GTFOBins to find a suitable exploit

    Why it's wrong here

    GTFOBins is a curated database of Unix binaries that can be abused to bypass local security restrictions, but it only lists well-known binaries with documented techniques. The tester's binary is not in the registry, so no suitable exploit entry exists; searching GTFOBins would be a dead end. More importantly, the binary already executes /bin/bash with root privileges due to the SUID bit, so the correct approach is to invoke that shell with the -p flag rather than rely on an external catalog. This option wastes time on reconnaissance when the privilege escalation path is already present in the binary's intended behavior.

  • ✗

    Perform a buffer overflow on the binary

    Why it's wrong here

    A buffer overflow would require a vulnerability in the binary’s source code, such as an unchecked input length, to overwrite memory and redirect execution. The stem states the binary already executes `/bin/bash` with root privileges via the SUID bit, so no memory corruption is needed—the tester can simply run the binary to gain a root shell. This option is tempting because buffer overflows are a common binary-exploitation technique for elevating privileges when a setuid binary lacks input validation, but here the intended functionality already provides root access.

  • ✓

    Run the binary with the -p flag

    Why this is correct

    When a SUID root binary executes /bin/bash, the kernel sets the effective UID to 0, but Bash normally resets the effective UID to the real UID to prevent privilege abuse. Running the binary with the -p flag forces Bash into privileged mode, preventing that reset and keeping the effective UID at 0. This yields a root shell with the user's real UID unchanged, making it the standard and direct privilege-escalation technique for SUID binaries that invoke a shell. The -p option is therefore the intended method to preserve the elevated privileges.

  • ✗

    Modify the PATH to include a fake binary

    Why it's wrong here

    PATH hijacking works only if the SUID binary invokes an external command without an absolute path, allowing an attacker to prepend a malicious directory. This technique fails here because the binary directly executes /bin/bash — an absolute, hardcoded path — rather than calling a command resolved through PATH. Additionally, modern SUID wrappers often sanitize environment variables, including PATH, to block such attacks. Since the binary already runs a shell as root, altering PATH does nothing; the privilege escalation requires invoking the shell with -p to preserve the effective UID.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.