PEN-200 Linux Privilege Escalation Practice Question
During a Linux privilege escalation assessment, you discover that the current user can run `/usr/bin/find` via sudo without a password. You execute `sudo find /home -exec /bin/bash \;`. What is the outcome?
⚠ Common exam trap
The trap here is assuming that -exec drops privileges or runs commands as the original user, when in fact it inherits the effective UID of the find process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A root shell is spawned because sudo runs find as root, and -exec executes /bin/bash with root privileges.
When a user is allowed to run find with sudo, they can leverage the -exec action to execute arbitrary commands as root. Because the entire find process runs with root privileges, any command spawned by -exec inherits those privileges. This allows an attacker to spawn a root shell, achieving privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A root shell is spawned because find's -exec runs the command as the invoking user, not root.
Why it's wrong here
This is incorrect because when find is executed via sudo, the entire process including its child commands runs with root privileges. The -exec action does not drop privileges; it inherits the effective UID of the parent process. Therefore, the spawned bash shell runs as root, not as the invoking user.
- ✗
The command fails because find does not allow -exec to run shell commands.
Why it's wrong here
find's -exec action is designed to run arbitrary commands on matched files. It does not restrict the command to non-shell binaries. Therefore, /bin/bash can be executed. The command will succeed and spawn a shell. The failure would occur only if the path to bash were incorrect or if find lacked execute permissions.
- ✗
A root shell is spawned only if the current user is a member of the sudo group.
Why it's wrong here
The sudo configuration already grants the current user permission to run this specific command. Whether the user is in the sudo group is irrelevant; sudoers rules can be defined for individual users or groups. The privilege escalation depends solely on the granted sudo rights, not on group membership.
- ✓
A root shell is spawned because sudo runs find as root, and -exec executes /bin/bash with root privileges.
Why this is correct
This is correct. When sudo executes find as root, the find process runs with an effective UID of 0. The -exec action forks and executes /bin/bash as a child of find, inheriting root privileges. Thus, an interactive root shell is obtained. This is a classic GTFOBins technique for privilege escalation.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.