Courseiva

CEH Enumeration and System Hacking Practice Question

A penetration tester successfully gains access to a Linux server as a low-privilege user. The goal is to escalate to root. Which THREE methods could the tester use to achieve privilege escalation?

⚠ Common exam trap

The trap here is that candidates mistake enumeration commands (like 'find / -perm -4000') for actual exploitation methods, or they assume /etc/shadow is accessible to low-privilege users without realizing it is root-protected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploit a vulnerable SUID binary to spawn a root shell

Option B is correct because a SUID binary executes with the file owner's privileges (typically root), so exploiting a vulnerable SUID program (e.g., via GTFOBins techniques or buffer overflow) can yield a root shell. Option C is correct because 'sudo -l' reveals the sudoers permissions for the current user, and misconfigurations such as NOPASSWD entries or allowed binaries like vim, find, or less can be abused to spawn a root shell. Option E is correct because a local kernel exploit matching the exact kernel version (verified with 'uname -r') can leverage a known vulnerability such as Dirty COW (CVE-2016-5195) or PwnKit to escalate to root. Option A is not a privilege escalation method by itself; 'find / -perm -4000' is only an enumeration step that identifies SUID binaries, which must then be exploited as in option B. Option D does not belong because /etc/shadow is normally readable only by root, so a low-privilege user cannot read the hashes; even if obtained, cracking them yields credentials rather than a direct escalation path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enumerate SUID binaries with 'find / -perm -4000'

    Why it's wrong here

    Enumerate SUID binaries with 'find / -perm -4000' is a crucial reconnaissance step in privilege escalation. This command identifies files that execute with the owner's permissions, often root, regardless of the user running them. However, merely listing these binaries does not *perform* privilege escalation; it only identifies potential targets for a subsequent exploit. It's a precursor, not the exploit itself.

  • ✓

    Exploit a vulnerable SUID binary to spawn a root shell

    Why this is correct

    Exploiting a vulnerable SUID binary is a direct and highly effective privilege escalation technique. If a program designed to run with root privileges (due to its SUID bit) contains a flaw, such as a buffer overflow, path injection, or insecure file handling, an attacker can manipulate it to execute arbitrary code. This allows the attacker to spawn a shell with root permissions, effectively gaining full control over the system.

  • ✓

    Use 'sudo -l' to list allowed commands and exploit misconfigurations

    Why this is correct

    Using 'sudo -l' allows a penetration tester to enumerate commands a user is permitted to run with `sudo` privileges, potentially without a password. If this list includes commands that can be leveraged to execute arbitrary code (e.g., `vi`, `less`, `nmap` with scripting engine, or `find` with `-exec`), or if a wildcard is present, the tester can exploit these misconfigurations. By invoking the allowed command in a specific way, a root shell can often be obtained, bypassing standard user restrictions.

  • ✗

    Check /etc/shadow for weak password hashes

    Why it's wrong here

    Checking /etc/shadow for weak password hashes is a post-exploitation activity focused on credential cracking, not a direct privilege escalation technique. While successfully cracking a root password hash would grant root access, the act of *checking* the file itself, or even attempting to crack it, does not elevate the current user's privileges. Accessing `/etc/shadow` typically requires root privileges already, or a separate vulnerability to read it, making this a subsequent step rather than the initial escalation.

  • ✓

    Run a local kernel exploit that matches the kernel version

    Why this is correct

    Running a local kernel exploit is a highly effective method for privilege escalation, provided a vulnerability exists in the operating system's kernel. These exploits leverage flaws such as race conditions, use-after-free bugs, or incorrect permission checks within the kernel itself. By successfully executing a matching exploit, an attacker can inject malicious code directly into kernel space, thereby gaining immediate root privileges and complete control over the system, often bypassing all userland security mechanisms.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.