GPEN Escalation and Exploitation Practice Question
You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)
⚠ Common exam trap
The trap here is treating any writable file or outdated package as an escalation, when only writable paths reachable by a root-owned execution context or sudo rights with command-injection flags actually yield root.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A systemd service unit that runs a script located in /opt/backup, and the /opt/backup directory is world-writable.
Two findings give direct root: a root-run service executing a script from a world-writable directory, allowing script replacement, and passwordless sudo for find, whose -exec flag spawns arbitrary commands. Both convert standard user access into root on the same host. The remaining findings are hygiene or lateral-movement issues that do not, by themselves, elevate privileges locally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The /etc/hosts file is writable by the standard user account you compromised.
Why it's wrong here
Writing to /etc/hosts lets you redirect hostname resolution, which can support name-resolution attacks or credential capture against other services, but it does not by itself elevate your privileges on this host. No root-owned process depends on that file in a way that executes your code. It is a lateral-movement aid, not a local root escalation.
- ✓
A systemd service unit that runs a script located in /opt/backup, and the /opt/backup directory is world-writable.
Why this is correct
A service unit that executes a script from a world-writable directory lets any local user replace that script with arbitrary code. Because the service runs as root under systemd, the replacement executes with root privileges on the next service start or restart. This is a direct and reliable escalation path from a standard user to root on the host.
- ✓
The sudoers file grants the account the right to run /usr/bin/find with the NOPASSWD tag.
Why this is correct
Granting passwordless sudo for find is dangerous because find supports the -exec flag, which runs arbitrary commands. A standard user can invoke find with -exec /bin/sh \; to obtain a root shell without supplying a password. This is a well-documented GTFOBins-style escalation and gives immediate root access on the host.
- ✗
The target runs an SSH server on port 22 that permits password authentication for all local accounts.
Why it's wrong here
Permitting password authentication on SSH only affects how remote logins are validated; it does not grant elevated rights to the user you already control. Without valid root credentials or another weakness, this setting provides no path to root. It may aid password spraying externally, but it is not a local escalation vector from the current session.
- ✗
The host has an outdated OpenSSL library version recorded in the package manifest.
Why it's wrong here
An outdated OpenSSL version is only exploitable if a reachable service uses the vulnerable code path and a working exploit exists for that exact version and configuration. Package version alone does not demonstrate exploitability, and OpenSSL flaws rarely yield straightforward local root from a standard user session. This is a hygiene finding, not a confirmed escalation path.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.