Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, the tester gains a Meterpreter session on a Windows target and wants to escalate privileges to SYSTEM. The current user has the SeImpersonatePrivilege token. Which tool should the tester use to exploit this privilege?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

PrintSpoofer exploits the SeImpersonatePrivilege to impersonate SYSTEM tokens.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer directly weaponizes SeImpersonatePrivilege: it creates a named pipe and abuses the Windows Print Spooler service to make a SYSTEM-level client connect and impersonate its token. Meterpreter sessions running as a service account with this privilege can use PrintSpoofer to instantly spawn a SYSTEM shell. Unlike suggestion or enumeration tools, it performs the actual privilege escalation, so it is the correct choice for this scenario.

  • ✗

    Windows-Exploit-Suggester

    Why it's wrong here

    Windows-Exploit-Suggester is a static analysis script that compares the target's security update level against a vulnerability database, outputting a list of potentially applicable exploits. It does not ship or execute these exploits, nor does it interact with the current meterpreter session to perform token impersonation. While it can guide an attacker to candidate CVEs, it leaves the actual SYSTEM escalation step to a separate tool, so it is not the answer here.

  • ✗

    whoami /priv

    Why it's wrong here

    The whoami /priv command enumerates the privileges held by the current token, such as SeImpersonatePrivilege, but it is purely a read-only diagnostic tool. It merely confirms that the environment may be exploitable; it cannot, by itself, create a process with a SYSTEM token or trigger a named-pipe impersonation attack. Since the question asks for a tool that escalates privileges, listing privileges is not a privilege escalation technique.

  • ✗

    Mimikatz

    Why it's wrong here

    Mimikatz is a post-exploitation toolkit focused on extracting plaintext passwords, LM/NTLM hashes, and Kerberos tickets from memory, then enabling pass-the-hash/ticket attacks. It does not provide a direct primitive for abusing SeImpersonatePrivilege to take over the Print Spooler pipe and access a SYSTEM token. Using it here would help move laterally or collect credentials, but it does not accomplish the local privilege escalation to SYSTEM described in the scenario.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.