Courseiva

PEN-200 Linux Privilege Escalation Practice Question

While enumerating a Linux host, you notice that the `passwd` command has the SUID bit set and is owned by root. You recall that SUID binaries run with the privileges of the file owner. Which of the following is the most direct way to leverage this to gain root access?

⚠ Common exam trap

The trap here is assuming that any SUID root binary is exploitable, when in fact many are standard and secure by design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SUID bit on `passwd` is standard and does not by itself allow privilege escalation.

The SUID bit on `/usr/bin/passwd` is a standard, secure configuration present on most Linux systems. It allows unprivileged users to change their own passwords by temporarily elevating privileges to write to `/etc/shadow`. This is not a vulnerability; the binary enforces strict access controls. Therefore, it does not provide a direct path to root. Testers should focus on non-standard SUID binaries or misconfigurations rather than expected ones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run `passwd` and change the root password.

    Why it's wrong here

    The `passwd` command, even with SUID root, enforces access controls: it only allows users to change their own password (or root to change any). A non-root user cannot change the root password because passwd checks the real UID and will deny the request. Therefore, this does not lead to privilege escalation. The SUID bit is necessary for passwd to write to /etc/shadow, but it does not bypass authentication for changing other users' passwords.

  • ✓

    The SUID bit on `passwd` is standard and does not by itself allow privilege escalation.

    Why this is correct

    The `passwd` command is commonly SUID root by default on many Linux distributions to allow users to change their own passwords by writing to `/etc/shadow`. This is a legitimate, expected configuration and does not constitute a vulnerability. Without an additional flaw or misconfiguration, the SUID bit on passwd cannot be leveraged for privilege escalation. Recognizing standard SUID binaries is crucial to avoid false positives during enumeration.

  • ✗

    Use the SUID bit to read the `/etc/shadow` file and crack the root hash.

    Why it's wrong here

    The `passwd` binary does not provide a mechanism to read `/etc/shadow`; it only allows writing to it under strict conditions. Even though it runs as root, it does not output the contents of shadow. There are other SUID binaries like `cat` or `more` that could read files if misconfigured, but `passwd` is designed to securely update password hashes, not display them. This option misunderstands the functionality of passwd.

  • ✗

    Exploit a vulnerability in the `passwd` binary to execute arbitrary code.

    Why it's wrong here

    While exploiting a vulnerability in a SUID binary is a valid technique, the question asks for the most direct way to leverage the SUID bit itself. The `passwd` binary is not inherently vulnerable; assuming a vulnerability exists without evidence is not reliable. The SUID bit alone does not provide a direct path to root unless the binary has a known flaw or misconfiguration. This option is speculative and not the intended answer.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.