Courseiva
Linux Privilege Escalation →mediumMultiple Choice

PEN-200 Linux Privilege Escalation Practice Question

Which command is most useful for identifying processes that are running as root, which might be potential targets for privilege escalation?

⚠ Common exam trap

Candidates often forget specific filtering flags or confuse process enumeration commands, attempting to use tools that do not display the file owners or trying to inspect user-level processes instead of focusing on root-owned services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ps aux | grep root

The 'ps' command is essential for process enumeration. By using specific flags like 'aux', you can display all processes running on the system, including their owner. Identifying services owned by root allows you to focus your efforts on finding vulnerabilities in those specific processes. This is a fundamental enumeration step, as privilege escalation often involves finding a misconfigured or vulnerable service that is already running with the target privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ps aux | grep root

    Why this is correct

    The 'ps aux' command lists every process on the system, and 'grep root' filters that list to show only those owned by the root user. This is the fastest way to identify all high-privilege services, which are the most valuable targets for your privilege escalation attempts.

  • ✗

    ls -l /proc

    Why it's wrong here

    Listing the /proc directory shows process IDs, but it doesn't immediately reveal the owner or the command being run for each process. While it provides access to process metadata, it is not as efficient or direct as using 'ps aux' for identifying processes owned by the root user.

  • ✗

    netstat -tulnp

    Why it's wrong here

    Netstat is used for network enumeration to find open ports and listening services. While it can show which service is listening on a port, it does not explicitly list the owner of every system process, making it an indirect and less effective way to identify root-owned processes.

  • ✗

    cat /etc/passwd | grep root

    Why it's wrong here

    This command only verifies that a root user exists on the system. It tells you nothing about the processes currently running or their security status. It is a system configuration check, not a process enumeration command, and is useless for finding exploitable services in an active environment.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.