CEH Enumeration and System Hacking Practice Question
A penetration tester successfully gains access to a Linux server as a low-privilege user. The goal is to escalate to root. Which THREE methods could the tester use to achieve privilege escalation?
⚠ Common exam trap
The trap here is that candidates mistake enumeration commands (like 'find / -perm -4000') for actual exploitation methods, or they assume /etc/shadow is accessible to low-privilege users without realizing it is root-protected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploit a vulnerable SUID binary to spawn a root shell
Option B is correct because a SUID binary executes with the file owner's privileges (typically root), so exploiting a vulnerable SUID program (e.g., via GTFOBins techniques or buffer overflow) can yield a root shell. Option C is correct because 'sudo -l' reveals the sudoers permissions for the current user, and misconfigurations such as NOPASSWD entries or allowed binaries like vim, find, or less can be abused to spawn a root shell. Option E is correct because a local kernel exploit matching the exact kernel version (verified with 'uname -r') can leverage a known vulnerability such as Dirty COW (CVE-2016-5195) or PwnKit to escalate to root. Option A is not a privilege escalation method by itself; 'find / -perm -4000' is only an enumeration step that identifies SUID binaries, which must then be exploited as in option B. Option D does not belong because /etc/shadow is normally readable only by root, so a low-privilege user cannot read the hashes; even if obtained, cracking them yields credentials rather than a direct escalation path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enumerate SUID binaries with 'find / -perm -4000'
Why it's wrong here
Enumerate SUID binaries with 'find / -perm -4000' is a crucial reconnaissance step in privilege escalation. This command identifies files that execute with the owner's permissions, often root, regardless of the user running them. However, merely listing these binaries does not *perform* privilege escalation; it only identifies potential targets for a subsequent exploit. It's a precursor, not the exploit itself.
- ✓
Exploit a vulnerable SUID binary to spawn a root shell
Why this is correct
Exploiting a vulnerable SUID binary is a direct and highly effective privilege escalation technique. If a program designed to run with root privileges (due to its SUID bit) contains a flaw, such as a buffer overflow, path injection, or insecure file handling, an attacker can manipulate it to execute arbitrary code. This allows the attacker to spawn a shell with root permissions, effectively gaining full control over the system.
- ✓
Use 'sudo -l' to list allowed commands and exploit misconfigurations
Why this is correct
Using 'sudo -l' allows a penetration tester to enumerate commands a user is permitted to run with `sudo` privileges, potentially without a password. If this list includes commands that can be leveraged to execute arbitrary code (e.g., `vi`, `less`, `nmap` with scripting engine, or `find` with `-exec`), or if a wildcard is present, the tester can exploit these misconfigurations. By invoking the allowed command in a specific way, a root shell can often be obtained, bypassing standard user restrictions.
- ✗
Check /etc/shadow for weak password hashes
Why it's wrong here
Checking /etc/shadow for weak password hashes is a post-exploitation activity focused on credential cracking, not a direct privilege escalation technique. While successfully cracking a root password hash would grant root access, the act of *checking* the file itself, or even attempting to crack it, does not elevate the current user's privileges. Accessing `/etc/shadow` typically requires root privileges already, or a separate vulnerability to read it, making this a subsequent step rather than the initial escalation.
- ✓
Run a local kernel exploit that matches the kernel version
Why this is correct
Running a local kernel exploit is a highly effective method for privilege escalation, provided a vulnerability exists in the operating system's kernel. These exploits leverage flaws such as race conditions, use-after-free bugs, or incorrect permission checks within the kernel itself. By successfully executing a matching exploit, an attacker can inject malicious code directly into kernel space, thereby gaining immediate root privileges and complete control over the system, often bypassing all userland security mechanisms.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.