PT0-002 Attacks and Exploits Practice Question
During a Windows privilege escalation attempt, the tester finds that the current user has SeImpersonatePrivilege enabled. Which THREE tools or techniques can be used to exploit this privilege?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JuicyPotato
PrintSpoofer, RoguePotato, and JuicyPotato exploit SeImpersonatePrivilege to gain SYSTEM. Mimikatz is for credential dumping, and PowerUp is a PowerShell script for privilege escalation but not specific to this privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
JuicyPotato
Why this is correct
JuicyPotato is a refined implementation of the Rotten Potato attack that abuses SeImpersonatePrivilege by leveraging COM object activation. It uses a DCOM server to trigger an NTLM authentication using the machine account, then duplicates the resulting token to execute arbitrary commands with SYSTEM integrity. This tool made the attack practical on Windows Server 2016 and later, although some methods were patched in current builds.
- ✗
Mimikatz
Why it's wrong here
Mimikatz is a credential theft tool that extracts plaintext passwords, NT hashes, and Kerberos tickets from LSASS memory, not a privilege escalation primitive. It does not exploit SeImpersonatePrivilege and requires an existing elevated context to perform many of its dumps. These credentials could enable lateral movement or escalate access, but Mimikatz itself does not directly abuse the impersonation privilege.
- ✓
RoguePotato
Why this is correct
RoguePotato is a newer variant that avoids the COM-server shortcomings of older potato exploits by using retransmitted NTLM authentication to a rogue server. It tricks the system into authenticating to an attacker-controlled endpoint, then uses the resulting token while having SeImpersonatePrivilege to spawn a SYSTEM process. This approach bypasses patches introduced for JuicyPotato on Windows unpatched versions, though it still ultimately depends on the same privilege.
- ✓
PrintSpoofer
Why this is correct
PrintSpoofer exploits SeImpersonatePrivilege by leveraging the Print Spooler service's ability to behave as a server for named pipes. An attacker creates a named pipe and causes the spooler to connect to it; the spooler process runs as SYSTEM, allowing the attacker to duplicate the SYSTEM token and execute commands with highest privileges. This technique is often used on Windows 10 and Server 2019 where older potato attacks are mitigated.
- ✗
PowerUp
Why it's wrong here
PowerUp is a PowerShell enumeration script that scans for common privilege-escalation misconfigurations such as weak folder permissions on services, unquoted service paths, and modifiable scheduled tasks. It does not specifically target SeImpersonatePrivilege and is not an exploitation tool; rather, it reports findings that might allow an attacker to escalate through service or task manipulation. Using it could inform an attacker of a path to SYSTEM, but it is not a direct SeImpersonate attack.
Go deeper
Related to this question
Learn chapter
Privilege Escalation on Windows
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
Key term
Mimikatz
Mimikatz is a powerful open-source tool used by attackers and security professionals to extract plaintext passwords, hashes, PINs, and Kerberos tickets from Windows memory.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.