Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

In a Windows domain, you have compromised a user account with SeImpersonatePrivilege enabled. Which tool or technique would best leverage this privilege to escalate to SYSTEM?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

SeImpersonatePrivilege allows token impersonation; PrintSpoofer exploits it to get SYSTEM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer is a well-known privilege escalation tool on Windows that exploits the SeImpersonatePrivilege typically held by service accounts. It leverages the Print Spooler's named pipe to trick a high-privileged process (SYSTEM) into connecting to a malicious pipe server, allowing the attacker to impersonate the SYSTEM token. This technique directly abuses token impersonation, making it the correct answer for a compromised user account with such privileges.

  • ✗

    AlwaysInstallElevated

    Why it's wrong here

    AlwaysInstallElevated is a Windows Installer policy misconfiguration where registry keys grant all users the right to install software with elevated SYSTEM privileges. Exploiting it involves crafting a malicious MSI package and running msiexec, not manipulating access tokens. It escalates privileges through Windows Installer's automatic elevation, but it does not rely on or interact with SeImpersonatePrivilege, so it is incorrect for this token-impersonation scenario.

  • ✗

    Pass-the-Hash with pth-winexe

    Why it's wrong here

    Pass-the-Hash (PtH) with pth-winexe is a lateral movement technique that reuses captured NTLM password hashes to authenticate to remote systems without knowing the plaintext password. It bypasses authentication entirely by submitting the hash as a credential, and pth-winexe establishes a Windows service on the target to gain a shell. This method does not involve token impersonation or SeImpersonatePrivilege, so it is not the right tool to escalate privileges on a local compromised account.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting is an offensive technique that targets domain service accounts by requesting Kerberos service tickets and attempting to crack the encrypted ticket hashes offline. It is a credential theft attack that exploits weak service account passwords, not token privileges. Kerberoasting has nothing to do with SeImpersonatePrivilege or token impersonation, making it an incorrect answer when trying to leverage impersonation privileges for privilege escalation.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.