GPEN Domain Escalation and Persistence Practice Question
Which THREE of the following are valid techniques for privilege escalation on a Linux system?
⚠ Common exam trap
Candidates often choose standard user permission configurations or weak password policies, failing to recognize specific structural mechanisms like SUID and sudoers entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploiting a binary with the SUID bit set to root.
Privilege escalation involves exploiting misconfigurations to gain higher access. Common vectors include exploiting SUID binaries, abusing SUDO rules that allow commands to run as root without passwords, and exploiting kernel vulnerabilities that allow arbitrary code execution in kernel mode. Understanding these vectors is crucial for identifying how an unprivileged user can transition to root and maintain control over the compromised Linux infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exploiting a binary with the SUID bit set to root.
Why this is correct
SUID binaries owned by root execute with root privileges. If the binary is vulnerable to buffer overflows or path injection, an attacker can hijack the execution flow to launch a root shell. This is a classic and highly effective privilege escalation path on many legacy Linux systems.
- ✗
Configuring a new user account with no password.
Why it's wrong here
Creating a new user account is not a privilege escalation technique; it is a persistence technique. While it provides access, it does not inherently escalate the user's current privileges. Furthermore, adding new accounts is highly visible to administrators and is likely to be detected by standard auditing tools.
- ✓
Abusing sudo permissions that allow specific command execution as root.
Why this is correct
If a user has sudo access to specific binaries like 'find', 'vim', or 'less', they can often escape these applications to drop into a root shell. This is a common misconfiguration where administrators grant broad 'sudo' access to specific tools without considering the potential for shell escaping.
- ✓
Exploiting kernel vulnerabilities to gain root-mode execution.
Why this is correct
Kernel vulnerabilities often allow for local privilege escalation by permitting arbitrary code execution within the kernel context. Once kernel code execution is achieved, an attacker can easily overwrite the credentials structure of the current process to change the effective user ID to zero, representing the root user.
- ✗
Renaming the /etc/passwd file to /etc/shadow.
Why it's wrong here
Renaming core system files will cause immediate system failure and is not a valid technique for privilege escalation. This action would disrupt system services and potentially lock out all users, including the root user, making it destructive rather than a useful method for gaining elevated control during a test.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.