CEH Enumeration and System Hacking Practice Question
A security team is investigating a compromised Linux server. They suspect the attacker used privilege escalation via SUID binaries. Which THREE techniques should the team check as potential attack vectors? (Choose THREE.)
⚠ Common exam trap
It's easy for candidates to confuse Windows-specific privilege escalation techniques (like token impersonation) with Linux SUID attacks, or incorrectly associate DDoS with local privilege escalation, leading them to select options B or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Injecting a malicious shared library via LD_PRELOAD into a SUID binary
Option A is correct because LD_PRELOAD can be abused to inject a malicious shared library into a SUID binary, causing the library's code to run with the binary's elevated privileges (though modern loaders ignore LD_PRELOAD for SUID binaries unless the binary is misconfigured or the library path is otherwise trusted). Option C is correct because SUID shell scripts are inherently dangerous: the shell may honor user-controlled environment variables such as PATH, IFS, or command names, letting an attacker execute arbitrary commands with the script's effective UID. Option E is correct because legitimate SUID binaries like nmap (with --interactive) or find (via -exec) can be abused to spawn a shell or run commands as root, a classic GTFOBins privilege-escalation vector. Option B is incorrect because SeDebugPrivilege and token impersonation are Windows access-token concepts, not Linux SUID mechanisms. Option D is incorrect because a DDoS attack targets availability and does not escalate privileges on the compromised Linux host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Injecting a malicious shared library via LD_PRELOAD into a SUID binary
Why this is correct
Injecting a malicious shared library via LD_PRELOAD into a SUID binary is a potent Linux privilege escalation technique. The LD_PRELOAD environment variable instructs the dynamic linker to load a specified shared library before any others, including standard system libraries. If this variable is set and a SUID binary is executed, the malicious library's functions can override legitimate ones, allowing an attacker to execute arbitrary code with the elevated privileges of the SUID binary's owner, typically root.
- ✗
Using token impersonation with SeDebugPrivilege
Why it's wrong here
Using token impersonation with SeDebugPrivilege is a privilege escalation method exclusively found within the Windows operating system security model. Token impersonation allows a process to temporarily assume the security context of another user or process, often facilitated by privileges like SeDebugPrivilege. Since the investigation is focused on a compromised Linux server, these Windows-specific mechanisms are entirely inapplicable and cannot be leveraged for privilege escalation in this environment.
- ✓
Leveraging a SUID shell script that calls a user-controlled command
Why this is correct
Leveraging a SUID shell script that calls a user-controlled command presents a significant privilege escalation vector. While shells often drop privileges when executing external commands, vulnerabilities arise if the SUID script executes commands using relative paths (e.g., `command` instead of `/bin/command`) or without fully qualifying paths. An attacker can then manipulate the `PATH` environment variable or place a malicious executable in a user-controlled directory, causing the script to execute the attacker's code with elevated privileges.
- ✗
Performing a DDoS attack on the server
Why it's wrong here
Performing a DDoS attack on the server is a denial-of-service technique aimed at disrupting the availability of a system or service by overwhelming it with traffic. While a successful DDoS attack can render a server inaccessible or unusable, it does not grant an attacker any elevated access rights, administrative privileges, or control over the system's internal functions. Therefore, it is not a method for privilege escalation.
- ✓
Exploiting a vulnerable SUID binary such as 'nmap' or 'find'
Why this is correct
Exploiting a vulnerable SUID binary such as 'nmap' or 'find' is a classic Linux privilege escalation technique. Certain legitimate SUID binaries, even if not inherently malicious, can contain built-in functionalities or specific vulnerabilities that allow for arbitrary command execution. For example, older versions of `nmap` could enter an interactive mode to execute commands as root, and `find` can execute commands via its `-exec` option. If these binaries are SUID, an attacker can craft specific arguments to spawn a shell or execute arbitrary commands with the privileges of the binary's owner.
Go deeper
Related to this question
Learn chapter
Denial of Service (DoS) and Distributed Denial of Service (DDoS)
Key term
Port Scanning Techniques
Port scanning techniques are methods used to probe a computer or network to discover which network ports are open and which services are running on those ports.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.