Courseiva

CEH Enumeration and System Hacking Practice Question

A security team is investigating a compromised Linux server. They suspect the attacker used privilege escalation via SUID binaries. Which THREE techniques should the team check as potential attack vectors? (Choose THREE.)

⚠ Common exam trap

It's easy for candidates to confuse Windows-specific privilege escalation techniques (like token impersonation) with Linux SUID attacks, or incorrectly associate DDoS with local privilege escalation, leading them to select options B or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injecting a malicious shared library via LD_PRELOAD into a SUID binary

Option A is correct because LD_PRELOAD can be abused to inject a malicious shared library into a SUID binary, causing the library's code to run with the binary's elevated privileges (though modern loaders ignore LD_PRELOAD for SUID binaries unless the binary is misconfigured or the library path is otherwise trusted). Option C is correct because SUID shell scripts are inherently dangerous: the shell may honor user-controlled environment variables such as PATH, IFS, or command names, letting an attacker execute arbitrary commands with the script's effective UID. Option E is correct because legitimate SUID binaries like nmap (with --interactive) or find (via -exec) can be abused to spawn a shell or run commands as root, a classic GTFOBins privilege-escalation vector. Option B is incorrect because SeDebugPrivilege and token impersonation are Windows access-token concepts, not Linux SUID mechanisms. Option D is incorrect because a DDoS attack targets availability and does not escalate privileges on the compromised Linux host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Injecting a malicious shared library via LD_PRELOAD into a SUID binary

    Why this is correct

    Injecting a malicious shared library via LD_PRELOAD into a SUID binary is a potent Linux privilege escalation technique. The LD_PRELOAD environment variable instructs the dynamic linker to load a specified shared library before any others, including standard system libraries. If this variable is set and a SUID binary is executed, the malicious library's functions can override legitimate ones, allowing an attacker to execute arbitrary code with the elevated privileges of the SUID binary's owner, typically root.

  • ✗

    Using token impersonation with SeDebugPrivilege

    Why it's wrong here

    Using token impersonation with SeDebugPrivilege is a privilege escalation method exclusively found within the Windows operating system security model. Token impersonation allows a process to temporarily assume the security context of another user or process, often facilitated by privileges like SeDebugPrivilege. Since the investigation is focused on a compromised Linux server, these Windows-specific mechanisms are entirely inapplicable and cannot be leveraged for privilege escalation in this environment.

  • ✓

    Leveraging a SUID shell script that calls a user-controlled command

    Why this is correct

    Leveraging a SUID shell script that calls a user-controlled command presents a significant privilege escalation vector. While shells often drop privileges when executing external commands, vulnerabilities arise if the SUID script executes commands using relative paths (e.g., `command` instead of `/bin/command`) or without fully qualifying paths. An attacker can then manipulate the `PATH` environment variable or place a malicious executable in a user-controlled directory, causing the script to execute the attacker's code with elevated privileges.

  • ✗

    Performing a DDoS attack on the server

    Why it's wrong here

    Performing a DDoS attack on the server is a denial-of-service technique aimed at disrupting the availability of a system or service by overwhelming it with traffic. While a successful DDoS attack can render a server inaccessible or unusable, it does not grant an attacker any elevated access rights, administrative privileges, or control over the system's internal functions. Therefore, it is not a method for privilege escalation.

  • ✓

    Exploiting a vulnerable SUID binary such as 'nmap' or 'find'

    Why this is correct

    Exploiting a vulnerable SUID binary such as 'nmap' or 'find' is a classic Linux privilege escalation technique. Certain legitimate SUID binaries, even if not inherently malicious, can contain built-in functionalities or specific vulnerabilities that allow for arbitrary command execution. For example, older versions of `nmap` could enter an interactive mode to execute commands as root, and `find` can execute commands via its `-exec` option. If these binaries are SUID, an attacker can craft specific arguments to spawn a shell or execute arbitrary commands with the privileges of the binary's owner.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.