Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester gains access to a Linux system and runs 'sudo -l', which reveals that the user can run /usr/bin/python with root privileges without a password. Which resource should the tester consult to find a method to escalate privileges using this configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GTFOBins

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions. It provides techniques for privilege escalation using binaries like python. GTFOBins is specifically for Unix privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PayloadsAllTheThings

    Why it's wrong here

    PayloadsAllTheThings is a broad repository of penetration testing payloads and techniques, but it is not purpose-built for identifying how to abuse a specific binary to escalate privileges when sudo permissions are misconfigured. Its sudo section is a small subset of a larger collection, whereas GTFOBins is a dedicated, exhaustive index of Unix binaries that can be exploited via sudo, capabilities, or SUID. Choosing PayloadsAllTheThings would require manually sifting through unrelated content, making it a less precise resource for this exact scenario.

  • ✓

    GTFOBins

    Why this is correct

    GTFOBins is the correct resource because it is a curated catalog of Unix binaries that can be abused to bypass local security restrictions, escalate privileges, or spawn shells — exactly what you need after running `sudo -l` and seeing a non-standard binary. It provides specific command snippets for each binary, categorized by functions like 'sudo', 'suid', and 'capabilities', so you can quickly match the binary you have access to with a privilege escalation vector. For a Linux penetration test, GTFOBins is the definitive reference for converting a misconfigured sudo entry into a root shell.

  • ✗

    HackTricks

    Why it's wrong here

    HackTricks is an extensive hacking wiki covering everything from web exploitation to post-exploitation, but it is not specialized for binary abuse. While it does list some GTFOBins-like examples, it lacks the systematic, per-binary coverage that GTFOBins offers, and its sudo section is more of an overview than a complete playbook. For a tester who needs a quick, authoritative answer on a specific binary seen in `sudo -l`, HackTricks is too broad and generalized to be the most direct resource—GTFOBins is the standard, purpose-specific reference.

  • ✗

    Exploit-DB

    Why it's wrong here

    Exploit-DB is a repository of actual proof-of-concept exploits and software vulnerabilities, but it is not designed to map a given Unix binary to a privilege escalation technique. Searching Exploit-DB for a binary like 'find' or 'vim' would yield historical CVE exploits, not the simple command sequences needed to leverage a sudo misconfiguration (e.g., `sudo find . -exec /bin/sh \;`). GTFOBins is the correct tool because it addresses the common scenario of a binary having an unintended sudo execution permission, which is a configuration weakness rather than a software vulnerability.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.