PEN-200 Linux Privilege Escalation Practice Question
A penetration tester discovers that the current user can write to a script located in /opt/backup/ that is executed every minute by a cron job running as root. The script has permissions `-rwxr-xr-x 1 root root`. What is the MOST reliable way to escalate privileges?
⚠ Common exam trap
The trap here is overcomplicating the attack with symlinks or permission changes when the script is already directly writable and executed by root.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the script to add a reverse shell command, then wait for the cron job to execute.
Because the script is writable and executed by root, an attacker can insert arbitrary commands that run with root privileges. Modifying the script to spawn a reverse shell or create a SUID backdoor is the most direct and reliable method. The cron job will execute the modified script as root, granting escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the `at` command to schedule a script that modifies the cron job.
Why it's wrong here
The `at` command schedules jobs for the current user, not root. It cannot modify root's cron jobs or execute commands as root. This approach does not leverage the existing misconfiguration and will not result in privilege escalation.
- ✗
Change the script's permissions to 777 and then execute it manually.
Why it's wrong here
Changing permissions does not escalate privileges because the script would still run as the current user when executed manually. The privilege escalation relies on the cron job executing the script as root, not on the script's permissions.
- ✗
Create a symbolic link to /etc/passwd in the same directory and modify the script to write to it.
Why it's wrong here
While symlink attacks can be effective in some contexts, this scenario already provides direct write access to the script itself. Creating a symlink adds unnecessary complexity and may not work if the script does not follow symlinks or if the cron job uses absolute paths. Direct modification is simpler and more reliable.
- ✓
Modify the script to add a reverse shell command, then wait for the cron job to execute.
Why this is correct
This is correct. Since the script is writable by the current user and executed by root via cron, modifying it to include a reverse shell or a command that creates a SUID binary will execute with root privileges. Waiting for the next cron interval triggers the escalation.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.