Courseiva
Linux Privilege Escalation →mediumMultiple Choice

PEN-200 Linux Privilege Escalation Practice Question

During a Linux privilege escalation assessment, you obtain a low-privileged shell as user 'student'. You run 'id' and see the user belongs to the 'docker' group. Which command will most reliably escalate to root on this host?

⚠ Common exam trap

The trap here is assuming that docker group membership only allows managing containers, when in fact it provides a direct path to host root via filesystem mounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

docker run -v /:/mnt --rm -it alpine chroot /mnt sh

Docker group membership allows a user to interact with the Docker daemon, which runs as root. By mounting the host root filesystem into a container and chrooting into it, an attacker can effectively gain root-level access to the host. This technique is well-known and reliable, as it leverages the daemon's privileges to bypass filesystem permissions. The other commands either require existing sudo rights, only change group context, or create isolated namespaces without host root privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    newgrp docker

    Why it's wrong here

    The newgrp command changes the current group ID to the specified group, in this case 'docker'. While it updates the shell's group context, it does not grant any additional privileges beyond what group membership already provides. It does not spawn a root shell or bypass any access controls. It is simply a way to activate a new group without logging out, and is not a privilege escalation method.

  • ✗

    unshare -Ur

    Why it's wrong here

    unshare -Ur creates a new user namespace and maps the current user to root within that namespace. This is often used for sandboxing or running unprivileged containers, but it does not grant real root privileges on the host system. The user remains unprivileged outside the namespace, and any actions inside are confined. It cannot be used to escalate to actual root on the host.

  • ✓

    docker run -v /:/mnt --rm -it alpine chroot /mnt sh

    Why this is correct

    Members of the docker group can control the Docker daemon, effectively giving root-level access to the host. This command starts a container, mounts the host's root filesystem at /mnt inside the container, and then uses chroot to change the root to /mnt, spawning a shell with root privileges on the host's filesystem. This is a classic and reliable privilege escalation technique when docker group membership is present.

  • ✗

    sudo -u root /bin/bash

    Why it's wrong here

    This command attempts to run /bin/bash as root via sudo. However, sudo typically requires the user to have explicit sudo privileges defined in /etc/sudoers or a sudoers.d file. Membership in the docker group does not grant any sudo rights. Running this would likely prompt for the user's password and then fail with 'user is not in the sudoers file' or a similar error, providing no escalation path.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.