GPEN Exploitation Fundamentals Practice Question
During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?
⚠ Common exam trap
The trap here is focusing on kernel exploits as the primary method, overlooking that misconfigurations like SUID binaries are often easier, safer, and more reliable for privilege escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Search for misconfigured SUID binaries and exploit them using GTFOBins techniques.
Privilege escalation via misconfigured SUID binaries is often the safest and most reliable because it exploits existing permissions rather than kernel vulnerabilities. Kernel exploits carry a higher risk of crashing the system and are version-dependent. Enumerating SUID binaries and using GTFOBins to identify exploitation vectors is a standard practice in penetration testing, allowing for privilege escalation without destabilizing the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a kernel exploit such as Dirty COW (CVE-2016-5195) to overwrite /etc/passwd and add a root user.
Why it's wrong here
Dirty COW is a powerful exploit but can be unreliable and may cause system crashes or corruption. It also requires specific conditions and may not work on all kernel versions. Overwriting /etc/passwd can leave obvious traces and may break system authentication. This method is riskier than leveraging misconfigurations.
- ✗
Use Metasploit's local exploit suggester module to automatically find and run a suitable exploit.
Why it's wrong here
While the local exploit suggester can identify potential exploits, it does not guarantee reliability or safety. It may suggest kernel exploits that could crash the system. Automated exploitation without manual verification can lead to unintended consequences. It is a useful tool for enumeration but not the most reliable method for safe privilege escalation.
- ✗
Use a public exploit for CVE-2017-16995 (BPF verifier) to gain root, as it is known to work on this kernel version.
Why it's wrong here
While CVE-2017-16995 affects certain kernel versions, it may not be reliable on all builds and could crash the system. Kernel exploits are version and configuration dependent; using one without verifying the exact patch level and environment can lead to instability. It is not the most reliable or safe method without further validation.
- ✓
Search for misconfigured SUID binaries and exploit them using GTFOBins techniques.
Why this is correct
This is often the most reliable and safe method because it leverages existing misconfigurations rather than exploiting kernel vulnerabilities. SUID binaries with known privilege escalation vectors (e.g., find, vim, nmap) can be exploited without causing system instability. It is also less likely to be detected by security controls and does not require kernel-specific exploits.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.