PT0-002 Attacks and Exploits Practice Question
During a penetration test, the tester gains a Meterpreter session on a Windows target and wants to escalate privileges to SYSTEM. The current user has the SeImpersonatePrivilege token. Which tool should the tester use to exploit this privilege?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PrintSpoofer
PrintSpoofer exploits the SeImpersonatePrivilege to impersonate SYSTEM tokens.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PrintSpoofer
Why this is correct
PrintSpoofer directly weaponizes SeImpersonatePrivilege: it creates a named pipe and abuses the Windows Print Spooler service to make a SYSTEM-level client connect and impersonate its token. Meterpreter sessions running as a service account with this privilege can use PrintSpoofer to instantly spawn a SYSTEM shell. Unlike suggestion or enumeration tools, it performs the actual privilege escalation, so it is the correct choice for this scenario.
- ✗
Windows-Exploit-Suggester
Why it's wrong here
Windows-Exploit-Suggester is a static analysis script that compares the target's security update level against a vulnerability database, outputting a list of potentially applicable exploits. It does not ship or execute these exploits, nor does it interact with the current meterpreter session to perform token impersonation. While it can guide an attacker to candidate CVEs, it leaves the actual SYSTEM escalation step to a separate tool, so it is not the answer here.
- ✗
whoami /priv
Why it's wrong here
The whoami /priv command enumerates the privileges held by the current token, such as SeImpersonatePrivilege, but it is purely a read-only diagnostic tool. It merely confirms that the environment may be exploitable; it cannot, by itself, create a process with a SYSTEM token or trigger a named-pipe impersonation attack. Since the question asks for a tool that escalates privileges, listing privileges is not a privilege escalation technique.
- ✗
Mimikatz
Why it's wrong here
Mimikatz is a post-exploitation toolkit focused on extracting plaintext passwords, LM/NTLM hashes, and Kerberos tickets from memory, then enabling pass-the-hash/ticket attacks. It does not provide a direct primitive for abusing SeImpersonatePrivilege to take over the Print Spooler pipe and access a SYSTEM token. Using it here would help move laterally or collect credentials, but it does not accomplish the local privilege escalation to SYSTEM described in the scenario.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.