PT0-002 Attacks and Exploits Practice Question
During a Windows privilege escalation attempt, a tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool can be used to exploit this privilege to gain SYSTEM access?
⚠ Common exam trap
PT0-003 often tests the mapping between a specific Windows privilege (SeImpersonatePrivilege, SeBackupPrivilege, SeDebugPrivilege) and the exact tool that abuses it — candidates confuse general-purpose tools like Mimikatz or PowerUp with the token-impersonation exploiters (PrintSpoofer, JuicyPotato, RoguePotato).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PrintSpoofer
PrintSpoofer exploits the SeImpersonatePrivilege by abusing the Windows Print Spooler service's named pipe (\\.\pipe\spoolss) to coerce a SYSTEM-level token and impersonate it, yielding NT AUTHORITY\SYSTEM. It is specifically designed for the SeImpersonatePrivilege/SeAssignPrimaryTokenPrivilege abuse class (alongside JuicyPotato, RoguePotato, and GodPotato). Because the question explicitly names SeImpersonatePrivilege, PrintSpoofer is the direct match.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PrintSpoofer
Why this is correct
PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to connect to a named pipe it controls, then impersonating the resulting token to gain SYSTEM. It satisfies the stem's Windows local escalation constraint directly, unlike token-stealing tools that require existing high-integrity tokens or kernel exploits.
- ✗
PowerUp
Why it's wrong here
PowerUp enumerates common Windows misconfigurations such as unquoted service paths and weak permissions; it does not abuse SeImpersonatePrivilege to impersonate a SYSTEM token. It is tempting as a general privilege-escalation toolkit, and would be correct for auditing service and registry weaknesses rather than token impersonation.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec automates SMB, WinRM and LDAP authentication across hosts for lateral movement and credential spraying; it does not exploit SeImpersonatePrivilege locally. It is tempting as a post-exploitation swiss army knife, and would be correct for enumerating or moving across a network once credentials are already held.
- ✗
Mimikatz
Why it's wrong here
Mimikatz extracts credentials, hashes and Kerberos tickets from memory; it does not exploit SeImpersonatePrivilege to obtain a SYSTEM token. It is tempting because it is the best-known Windows credential tool, and would be correct for dumping LSASS secrets or performing pass-the-hash after elevation, not for the elevation itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.