Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

While exploiting a Windows machine, a tester gains a shell with limited privileges. They attempt to escalate privileges using a tool that exploits the SeImpersonatePrivilege. Which tool is specifically designed for this purpose on modern Windows versions?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PrintSpoofer

PrintSpoofer exploits SeImpersonatePrivilege on Windows 10/Server 2016+ to gain SYSTEM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mimikatz

    Why it's wrong here

    Mimikatz is a post-exploitation tool focused on extracting credentials (e.g., LSASS memory, SAM hive, Kerberos tickets) to enable lateral movement or impersonation via cached secrets, not on abusing SeImpersonatePrivilege. Though it can be used to 'over-pass-the-hash' or dump plaintext passwords, it does not interact with the token impersonation primitive that PrintSpoofer exploits. On a machine where the tester already has a service-level shell with SeImpersonate, Mimikatz would not directly escalate to SYSTEM; it would only recover credentials for other access paths.

  • ✗

    JuicyPotato

    Why it's wrong here

    JuicyPotato is an older incarnation of the Potato attack family that abuses SeImpersonatePrivilege by relaying NTLM authentication from a DCOM call to a local, privileged token. This technique famously breaks on Windows 10 1809 and Server 2016/2019 due to changes in how the Print Spooler and DCOM handle impersonation, as well as the introduction of PPL (Protected Process Light). Given that the scenario implies a reliable modern-era escalation, JuicyPotato is wrong because it would likely fail against Windows 10/Server 2016+ targets where PrintSpoofer is the designed solution.

  • ✓

    PrintSpoofer

    Why this is correct

    PrintSpoofer is the correct tool for Windows 10/Server 2016 and later when the compromised account holds SeImpersonatePrivilege. It works by tricking the Print Spooler service into impersonating the user via its named pipe, then using that impersonated token to launch a SYSTEM process (e.g., cmd.exe). Unlike JuicyPotato's DCOM-based NTLM relay, PrintSpoofer doesn't rely on outdated COM handshakes, making it far more reliable on modern builds. Its name is misleading—it's not exploiting a vulnerability in the spooler, but abusing an advertised impersonation feature to elevate privileges.

  • ✗

    PowerUp

    Why it's wrong here

    PowerUp is an enumeration-first PowerShell tool that discovers common privilege escalation weaknesses such as unquoted service paths, writable service binaries, and AlwaysInstallElevated; it does not directly exploit SeImpersonatePrivilege. It can run quick checks and even attempt to exploit some service misconfigurations, but it has no mechanism to impersonate another user's token. Therefore, when the goal is specifically to turn SeImpersonate into SYSTEM, PowerUp serves as a discovery aid—not the tool actually used for the token-based attack.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.