Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a Windows privilege escalation attempt, a tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool can be used to exploit this privilege to gain SYSTEM access?

⚠ Common exam trap

PT0-003 often tests the mapping between a specific Windows privilege (SeImpersonatePrivilege, SeBackupPrivilege, SeDebugPrivilege) and the exact tool that abuses it — candidates confuse general-purpose tools like Mimikatz or PowerUp with the token-impersonation exploiters (PrintSpoofer, JuicyPotato, RoguePotato).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

PrintSpoofer exploits the SeImpersonatePrivilege by abusing the Windows Print Spooler service's named pipe (\\.\pipe\spoolss) to coerce a SYSTEM-level token and impersonate it, yielding NT AUTHORITY\SYSTEM. It is specifically designed for the SeImpersonatePrivilege/SeAssignPrimaryTokenPrivilege abuse class (alongside JuicyPotato, RoguePotato, and GodPotato). Because the question explicitly names SeImpersonatePrivilege, PrintSpoofer is the direct match.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to connect to a named pipe it controls, then impersonating the resulting token to gain SYSTEM. It satisfies the stem's Windows local escalation constraint directly, unlike token-stealing tools that require existing high-integrity tokens or kernel exploits.

  • ✗

    PowerUp

    Why it's wrong here

    PowerUp enumerates common Windows misconfigurations such as unquoted service paths and weak permissions; it does not abuse SeImpersonatePrivilege to impersonate a SYSTEM token. It is tempting as a general privilege-escalation toolkit, and would be correct for auditing service and registry weaknesses rather than token impersonation.

  • ✗

    CrackMapExec

    Why it's wrong here

    CrackMapExec automates SMB, WinRM and LDAP authentication across hosts for lateral movement and credential spraying; it does not exploit SeImpersonatePrivilege locally. It is tempting as a post-exploitation swiss army knife, and would be correct for enumerating or moving across a network once credentials are already held.

  • ✗

    Mimikatz

    Why it's wrong here

    Mimikatz extracts credentials, hashes and Kerberos tickets from memory; it does not exploit SeImpersonatePrivilege to obtain a SYSTEM token. It is tempting because it is the best-known Windows credential tool, and would be correct for dumping LSASS secrets or performing pass-the-hash after elevation, not for the elevation itself.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.