Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a Windows privilege escalation attempt, the tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool is commonly used to exploit this privilege to gain SYSTEM?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

PrintSpoofer exploits SeImpersonatePrivilege to impersonate SYSTEM and spawn a shell.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to authenticate against a named pipe it controls, then impersonating the resulting token to obtain SYSTEM. It targets Windows 10 and Server 2019+, where Rotten Potato techniques fail, satisfying the scenario's requirement for a working SeImpersonate escalation path.

  • ✗

    SharpUp

    Why it's wrong here

    SharpUp audits Windows host misconfigurations — unquoted service paths, weak service permissions, modifiable autoruns — and reports findings; it does not itself impersonate a token. It is tempting because it enumerates privilege-escalation vectors, and would be the right pick when the task is identifying weaknesses rather than exploiting SeImpersonatePrivilege, which tools such as PrintSpoofer or GodPotato handle.

  • ✗

    Mimikatz

    Why it's wrong here

    Mimikatz harvests credentials and forges Kerberos tickets from memory; it does not abuse SeImpersonatePrivilege to obtain a SYSTEM token. It is tempting because it excels at credential dumping and pass-the-hash during post-exploitation, where extracting cached logons or tickets is the goal rather than token impersonation.

  • ✗

    PowerUp

    Why it's wrong here

    PowerUp enumerates Windows misconfigurations such as unquoted service paths and weak service permissions; it does not exploit SeImpersonatePrivilege to obtain SYSTEM. It is tempting because it is a privilege-escalation script, and it would be the right choice when hunting for those configuration weaknesses rather than abusing token impersonation.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.