Courseiva
Linux Privilege Escalation →mediumMultiple Choice

PEN-200 Linux Privilege Escalation Practice Question

You find that a binary relies on a relative path to execute a secondary script. If you cannot modify the PATH variable, what is the best alternative to exploit this configuration?

⚠ Common exam trap

Test-takers frequently assume they can simply modify the system PATH variable even when they lack the necessary administrative write permissions, leading them down a dead end.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the expected directory structure in a location you control and execute the binary from there.

If PATH modification is not possible, you can utilize symlinks or directory traversal to manipulate the binary's search logic. By creating a directory structure that mimics the expected relative path, you can place a malicious executable where the binary expects the legitimate one. This is effective because it exploits the binary's reliance on current working directory context, bypassing strict system-wide path settings entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the binary's ELF header to change the search path.

    Why it's wrong here

    Modifying an ELF header is extremely complex and typically requires a deep understanding of binary structure. Furthermore, the file would likely fail integrity checks if it is signed or if the filesystem is read-only. This is not a standard or reliable method for privilege escalation in testing environments.

  • ✓

    Create the expected directory structure in a location you control and execute the binary from there.

    Why this is correct

    If the binary expects to find a script in a relative path like './scripts/run.sh', you can create a directory named 'scripts' in your current location and place a malicious 'run.sh' inside. When the binary runs, it will find and execute your script, inheriting the binary's SUID privileges.

  • ✗

    Use the 'ptrace' system call to attach to the binary and change its execution flow.

    Why it's wrong here

    Ptrace is often blocked by kernel security settings like YAMA, which prevent one process from attaching to another, especially SUID binaries. Even if it were not blocked, the complexity of manipulating the process execution flow via ptrace makes it a far less efficient approach than exploiting relative path lookups.

  • ✗

    Inject environment variables like 'LD_LIBRARY_PATH' to overwrite the binary's functionality.

    Why it's wrong here

    While LD_LIBRARY_PATH can be used to load malicious libraries, it does not resolve the issue of executing a secondary script via a relative path. The binary will still look for the script in the relative directory, regardless of which libraries are loaded, rendering this approach ineffective for this goal.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.