PEN-200 Linux Privilege Escalation Practice Question
Which Linux kernel feature, if misconfigured or outdated, allows an unprivileged user to gain root access by exploiting a vulnerability in the handling of user namespaces?
⚠ Common exam trap
Candidates often confuse user namespace features with standard file permissions or misconfigured SUID binaries, looking in the wrong places for kernel-level escalation vectors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unprivileged user namespace clone functionality
User namespaces allow unprivileged processes to behave as root within a confined environment. Vulnerabilities in how the kernel manages these namespaces, such as improper capability checks, can be exploited to gain full root access on the host system. This highlights the importance of kernel patching and minimizing the attack surface by disabling unnecessary namespace features on production servers to prevent escapes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AppArmor profile confinement
Why it's wrong here
AppArmor is a Mandatory Access Control system designed to restrict programs' capabilities. It is not a feature you exploit to gain privileges; rather, it is a defensive layer that prevents exploitation. Misconfiguration of AppArmor usually leads to a more restricted state, not an escalation path for the user.
- ✓
Unprivileged user namespace clone functionality
Why this is correct
The 'unshare' or 'clone' syscalls allow creating new namespaces without root. Exploits often target how the kernel handles these namespaces to escalate privileges. Because these features are often exposed to all users, they serve as a critical vector for local privilege escalation attacks on outdated kernels.
- ✗
Shared memory segment access via IPC
Why it's wrong here
Inter-process communication (IPC) vulnerabilities can sometimes lead to information disclosure or crashes, but they are not the primary mechanism for namespace-based privilege escalation. While interesting for local research, they do not offer the same reliability as direct namespace exploitation for gaining full root access on Linux systems.
- ✗
Extended file attributes (xattr)
Why it's wrong here
Extended attributes are used for storing metadata about files, such as security labels. While they are crucial for systems like SELinux, they do not provide a path for privilege escalation through namespace manipulation. They are a passive storage mechanism and are not directly involved in the kernel's process isolation architecture.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.