PT0-002 Attacks and Exploits Practice Question
During a penetration test, you run the following command on a Linux target: `find / -type f -perm /4000 2>/dev/null`. What are you attempting to identify?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SUID binaries
The find command with -perm /4000 searches for files with SUID bit set, which can be exploited for privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
World-writable files
Why it's wrong here
World-writable files are identified by their write permissions for the 'others' class, typically shown as a trailing 2 in the permission mode (e.g., 0666 or 0777). The `-perm /4000` argument does not evaluate write bits at all; instead it tests for the setuid bit (4000 octal). Therefore, a world-writable file without SUID will not be matched, making this option incorrect.
- ✓
SUID binaries
Why this is correct
This is the correct answer because `-perm /4000` instructs `find` to locate any file where the set-user-ID (SUID) permission bit is set, regardless of other permission bits. In octal, 4000 corresponds specifically to the SUID bit, and the leading `/` means 'any of these bits' (here just 4000). When a binary has SUID set, it executes with the file owner's privileges, which makes SUID binaries a high-priority target for privilege escalation during a penetration test.
- ✗
Files with extended attributes
Why it's wrong here
Files with extended attributes rely on metadata stored in separate namespaces (e.g., `user`, `security`, `trusted`) and are not represented by traditional octal permission bits. The `find -perm` expression matches only the standard permission mode, and `4000` is an octal bitmask for SUID, not an extended-attribute indicator. To locate such files, a tester would use `find` with `-xattr` or inspect them with `getfattr`, so this option is incorrect.
- ✗
SGID binaries
Why it's wrong here
SGID (set-group-ID) is encoded as the octal bit 2000, not 4000. The `-perm /4000` mask specifically tests only the SUID bit, so a binary with SGID set but SUID unset would not match. If the goal were to find SGID files, a correct command would be `find / -perm /2000` or `-perm /6000` to catch both setuid and setgid, making this option incorrect.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.