PEN-200 Linux Privilege Escalation Practice Question
You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?
⚠ Common exam trap
Candidates often assume the binary is vulnerable because it is SUID, forgetting that they must actually manipulate the environment to redirect the binary's execution to their own malicious code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prepend a directory containing a malicious 'cat' script to the PATH variable and run the binary.
By manipulating the PATH environment variable, you can point the system to a malicious 'cat' executable created in a writable directory. When the SUID binary runs, it executes your script with the permissions of the file owner rather than yours. This technique exploits the insecure execution of external commands, a common vulnerability in improperly coded SUID binaries that allows for arbitrary command execution under an elevated security context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Overwrite the SUID binary's source code in /usr/src to include a reverse shell.
Why it's wrong here
Source code is typically not stored on production systems, and modifying it would not affect the pre-compiled binary currently on the disk. Even if the source were present, write access to /usr/src is rarely granted to low-privileged users, making this method ineffective for privilege escalation during standard testing.
- ✗
Use 'chmod' to grant everyone execute permissions on the SUID binary to trigger a buffer overflow.
Why it's wrong here
Changing permissions with chmod requires write access to the binary or root privileges, which the user lacks. Furthermore, triggering a buffer overflow requires a specific memory vulnerability in the application, not just changing execute permissions. This approach fails to address the underlying privilege escalation path required for root.
- ✓
Prepend a directory containing a malicious 'cat' script to the PATH variable and run the binary.
Why this is correct
By creating a script named 'cat' in a directory like /tmp and setting the PATH variable to start with that directory, the system executes your script instead of the legitimate binary. Because the parent program is SUID root, your malicious script runs with root privileges, granting a shell.
- ✗
Modify the /etc/ld.so.preload file to inject a malicious library into the SUID binary's execution flow.
Why it's wrong here
Modifying /etc/ld.so.preload requires root privileges because it is a system-wide configuration file. A low-privileged user cannot write to this file, making it impossible to perform library injection. This method is ineffective unless the user has already achieved some level of elevated access or a specific misconfiguration exists.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.