PEN-200 Linux Privilege Escalation Practice Question
Which command is most useful for identifying processes that are running as root, which might be potential targets for privilege escalation?
⚠ Common exam trap
Candidates often forget specific filtering flags or confuse process enumeration commands, attempting to use tools that do not display the file owners or trying to inspect user-level processes instead of focusing on root-owned services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ps aux | grep root
The 'ps' command is essential for process enumeration. By using specific flags like 'aux', you can display all processes running on the system, including their owner. Identifying services owned by root allows you to focus your efforts on finding vulnerabilities in those specific processes. This is a fundamental enumeration step, as privilege escalation often involves finding a misconfigured or vulnerable service that is already running with the target privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ps aux | grep root
Why this is correct
The 'ps aux' command lists every process on the system, and 'grep root' filters that list to show only those owned by the root user. This is the fastest way to identify all high-privilege services, which are the most valuable targets for your privilege escalation attempts.
- ✗
ls -l /proc
Why it's wrong here
Listing the /proc directory shows process IDs, but it doesn't immediately reveal the owner or the command being run for each process. While it provides access to process metadata, it is not as efficient or direct as using 'ps aux' for identifying processes owned by the root user.
- ✗
netstat -tulnp
Why it's wrong here
Netstat is used for network enumeration to find open ports and listening services. While it can show which service is listening on a port, it does not explicitly list the owner of every system process, making it an indirect and less effective way to identify root-owned processes.
- ✗
cat /etc/passwd | grep root
Why it's wrong here
This command only verifies that a root user exists on the system. It tells you nothing about the processes currently running or their security status. It is a system configuration check, not a process enumeration command, and is useless for finding exploitable services in an active environment.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.