Courseiva
easyMultiple Select

PT0-002 Practice Question: Which THREE of the following are example of…

Which THREE of the following are example of privilege escalation techniques on Linux systems? (Select THREE.)

⚠ Common exam trap

CompTIA often tests the distinction between Windows-specific and Linux-specific privilege escalation techniques, so the trap here is that candidates may mistakenly apply Windows concepts like token manipulation or pass-the-hash to Linux environments, where they are not valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploiting kernel vulnerabilities

Option A is correct because exploiting kernel vulnerabilities (e.g., Dirty COW CVE-2016-5195 or Dirty Pipe CVE-2022-0847) lets a local unprivileged user execute code in kernel context and gain root, a classic Linux privilege-escalation technique. Option B is correct because SUID binaries run with the file owner's privileges (often root), so abusing a vulnerable or misconfigured SUID program (e.g., via GTFOBins techniques) elevates a normal user to root. Option D is correct because sudo misconfiguration—such as overly permissive entries in /etc/sudoers (e.g., NOPASSWD or allowed commands like vi, find, or python)—lets a user run commands as root and escalate privileges. Option C (token manipulation) is a Windows access-token concept (e.g., SeDebugPrivilege/token stealing), not a standard Linux escalation technique. Option E (pass-the-hash) is a Windows/Active Directory credential-reuse attack against NTLM hashes, not applicable to Linux privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Exploiting kernel vulnerabilities

    Why this is correct

    Kernel vulnerabilities are a classic local privilege escalation vector because the kernel executes in the most privileged CPU ring (ring 0 on x86). A flaw such as a use-after-free or missing permission check in a syscall handler lets an unprivileged user execute arbitrary code with kernel or root privileges. Exploits like Dirty COW (CVE-2016-5195) and CVE-2022-0847 (Dirty Pipe) demonstrate how a low-privileged attacker can overwrite read-only files or gain root, making this a primary target for post-exploitation.

  • ✓

    Exploiting SUID binary vulnerabilities

    Why this is correct

    SUID binaries execute with the file owner's privileges, so a flaw in a root-owned SUID program lets an unprivileged user run code as root, which is a classic Linux privilege escalation vector and satisfies the stem's requirement for an escalation technique.

  • ✗

    Token manipulation

    Why it's wrong here

    Token manipulation is specifically a Windows access token attack, where an attacker duplicates or impersonates a token (e.g., using `DuplicateTokenEx` or `ImpersonateLoggedOnUser`) to act with the privileges of another user or system account. While this is a legitimate privilege escalation technique in Windows, the question asks for general examples, and this answer is marked wrong because it is platform-specific and does not apply to Linux or other Unix-like systems. In a PenTest+ context, token manipulation is better categorized as a Windows credential and lateral movement technique rather than a universal privilege escalation example.

  • ✓

    Sudo misconfiguration exploitation

    Why this is correct

    Sudo misconfiguration exploitation occurs when a user is granted sudo rights to specific commands or scripts without proper path or argument restrictions. For instance, a sudoers entry allowing `sudo vim` or `sudo python` effectively grants root because these programs can spawn a shell (`:!bash` or `import pty; pty.spawn('/bin/bash')`). Unlike kernel or SUID flaws, this is a configuration error rather than a software vulnerability, but it is a common and easily demonstrated privilege escalation path on Linux systems.

  • ✗

    Pass-the-hash

    Why it's wrong here

    Pass-the-hash is a post-exploitation lateral movement technique used in Windows environments to authenticate as a user by replaying an NTLM hash without knowing the plaintext password. It does not inherently escalate privileges from a lower-privileged account to a higher one; instead, it reuses existing credentials to move across systems. In the context of privilege escalation, it is often confused with techniques like token manipulation, but its primary purpose is maintaining access or expanding within a network, not elevating the privilege level of the current process.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.