Courseiva
Linux Privilege Escalation →mediumMultiple Choice

PEN-200 Linux Privilege Escalation Practice Question

Why is it often effective to check for 'Capabilities' on Linux binaries when SUID is not present?

⚠ Common exam trap

Students often ignore binaries lacking the SUID bit entirely, assuming they are secure, and completely overlook alternative mechanisms like Linux capabilities during enumeration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They allow a binary to perform privileged operations without full root UID.

Linux capabilities allow for fine-grained control over privileged operations, such as network raw socket access or file modification, without requiring the full root user. If a binary has excessive capabilities assigned, it can be abused to perform privileged actions. This is a subtle but powerful alternative to SUID that is frequently overlooked during security assessments, making it a valuable path for privilege escalation when traditional SUID targets are unavailable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Capabilities are automatically granted to all users on a system.

    Why it's wrong here

    Capabilities are not granted to users by default; they are assigned to executables. Granting capabilities to all users would be a massive security vulnerability that modern Linux distributions avoid. They are intended for specific tasks where a program needs limited root privileges rather than unrestricted access.

  • ✓

    They allow a binary to perform privileged operations without full root UID.

    Why this is correct

    Capabilities break down root privileges into smaller units. If a binary is granted the 'CAP_DAC_OVERRIDE' capability, for example, it can bypass file permission checks even if the binary itself isn't running as root. This allows for privilege escalation by leveraging the binary's authorized, high-level permissions.

  • ✗

    Capabilities only work on binaries that have the SUID bit set.

    Why it's wrong here

    Capabilities and SUID are two distinct mechanisms for privilege management. In fact, capabilities are often used to replace SUID to minimize the attack surface. They can be applied to binaries regardless of whether the SUID bit is set, which is exactly why they are an important, independent enumeration target.

  • ✗

    They enable the user to bypass the sudo password prompt.

    Why it's wrong here

    Capabilities have nothing to do with the sudoers file or password prompts. They are managed by the kernel's security modules. While they can lead to privilege escalation, they operate completely independently of the sudo mechanism, making this an incorrect association between two unrelated security features.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.