PEN-200 Linux Privilege Escalation Practice Question
You have a low-privileged shell on a Linux host. You discover a cron job that runs every minute as root and executes a script located at /opt/backup/backup.sh. The script is world-writable. However, you also notice that the directory /opt/backup is owned by root and has permissions 755. Which of the following is the MOST reliable way to escalate privileges?
⚠ Common exam trap
The trap here is focusing on the directory permissions and assuming you cannot modify the script, when in fact the file itself is writable and that is sufficient to inject commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overwrite the backup.sh script with a reverse shell payload.
The script is world-writable, so you can modify its contents directly. Because the cron job executes it as root, any commands you insert will run with root privileges. A reverse shell payload is a common and effective method. The directory permissions prevent replacing the file or creating symlinks, but do not prevent editing the file's contents. Therefore, overwriting the script is the most reliable approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the backup.sh script with a symbolic link to a file you control.
Why it's wrong here
Replacing the script with a symlink requires write permission on the directory to delete the existing file and create a symlink. Since /opt/backup is owned by root with 755 permissions, a low-privileged user cannot delete or rename files in that directory. Thus, you cannot replace the script with a symlink, even though the file itself is writable.
- ✗
Modify the script to add a new user with UID 0 to /etc/passwd.
Why it's wrong here
While modifying the script is possible, adding a user to /etc/passwd requires root privileges to write to that file. The script runs as root, so it could modify /etc/passwd, but the modification would be effective only if the script executes your added commands. However, the script is executed as root, so it could indeed add a user. But this is less direct than a reverse shell and may be detected. The question asks for the most reliable way; overwriting with a reverse shell is more straightforward.
- ✗
Use the `crontab` command to edit the root user's crontab and add a new job.
Why it's wrong here
The crontab command requires appropriate permissions to edit another user's crontab. As a low-privileged user, you cannot edit root's crontab without sudo access. The cron job is already running as root, and you can exploit the writable script directly. This option is not feasible without additional privileges.
- ✓
Overwrite the backup.sh script with a reverse shell payload.
Why this is correct
The script is world-writable, meaning any user can modify its contents. Since the cron job runs as root, overwriting the script with a payload that creates a SUID root shell or connects back to your listener will execute with root privileges. The directory permissions do not prevent modifying the file's contents because the file itself is world-writable. This is a direct and reliable escalation.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.