PEN-200 Linux Privilege Escalation Practice Question
When performing a kernel exploit for privilege escalation, what is the most significant risk to the stability of the target system?
⚠ Common exam trap
Candidates often fear being 'caught' by an IDS/IPS. While that is a risk, the immediate, most significant technical risk of a kernel exploit is crashing the target machine entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system might experience a kernel panic, causing a complete crash.
Kernel exploits operate at the lowest level of the operating system. If the exploit code contains errors or interacts incorrectly with kernel memory structures, it can lead to a kernel panic, crashing the entire system. This is a significant operational risk, as it results in downtime and potentially triggers alerts that lead to discovery, emphasizing the need for caution and testing exploits in isolated environments before deployment on production targets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system will automatically log the attacker's IP address.
Why it's wrong here
Kernel exploits do not inherently log the attacker's source IP address. While network-based systems might detect the traffic, the kernel itself is not logging the source of the exploit code. The primary risk is system stability, not the leakage of the attacker's network identity via the kernel.
- ✓
The system might experience a kernel panic, causing a complete crash.
Why this is correct
Because kernel exploits manipulate sensitive memory structures and CPU instructions, any mistake or unexpected state will trigger a kernel panic. This results in an immediate and total system crash, which is a major risk when attempting privilege escalation on live systems that need to remain operational.
- ✗
The exploit will permanently delete all data on the disk.
Why it's wrong here
Kernel exploits are designed to manipulate the execution flow to gain privileges, not to destroy data. While a crash could lead to filesystem corruption, intentional data destruction is not the goal or the standard outcome of an exploit, as it would defeat the purpose of gaining persistent, functional access.
- ✗
The system firewall will automatically block the user account.
Why it's wrong here
Firewalls operate at the network layer and are not configured to block local user accounts based on kernel activity. While an intrusion detection system might identify malicious patterns, the kernel itself has no mechanism to disable a user account in response to a failed local exploit attempt.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.