PEN-200 Linux Privilege Escalation Practice Question
Exhibit
id uid=1001(web) gid=1001(web) groups=1001(web) find / -perm -u=s -type f 2>/dev/null /usr/bin/find /usr/bin/passwd /usr/bin/sudo
Refer to the exhibit. The 'find' binary has the SUID bit set. How can you leverage this to gain a root shell?
⚠ Common exam trap
Candidates frequently omit the critical '-p' flag when spawning a shell via SUID binaries, causing the shell to drop privileges and preventing root access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
find . -exec /bin/sh -p \;
The 'find' command includes an '-exec' flag that allows executing arbitrary commands on the files it locates. When an SUID-bit 'find' binary is used with the '-exec' flag, the command spawned by '-exec' will also run with the SUID owner's privileges. This is a well-documented technique for privilege escalation, demonstrating why SUID binaries must be audited to ensure they do not offer functionality that can be abused for command execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
find . -exec /bin/sh -p \;
Why this is correct
Using the -exec flag with /bin/sh allows you to spawn a shell. The -p flag is essential for 'sh' to maintain the SUID privilege level instead of dropping it to the user's real UID. This command effectively drops you into a root shell because 'find' is executing as root.
- ✗
find . -name "*" -delete
Why it's wrong here
The -delete flag simply removes files matching the criteria. It does not allow for shell execution or command injection. While it could cause system instability or data loss, it does not lead to privilege escalation or the gain of a shell, making it irrelevant for this specific security goal.
- ✗
find . -exec chmod 777 /etc/shadow \;
Why it's wrong here
While this command would make /etc/shadow world-readable, it does not grant you a shell or immediate root access. You would still need to crack the hashes to get the root password. This is a much slower and less direct method than spawning a shell using the SUID binary.
- ✗
find / -user web -exec ls -l {}
Why it's wrong here
This command only lists files owned by the user 'web'. It does not execute any dangerous actions and does not leverage the SUID bit of the 'find' binary to perform any privileged operations. It is a standard enumeration command and has no impact on privilege escalation.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.