ExamQuestions.com

Register
Login
CompTIA Advanced Security Practitioner (CASP+) CAS-004 Exam Questions

CompTIA

CompTIA Advanced Security Practitioner (CASP+) CAS-004

29 / 44

Question 29:

During a system penetration test, a security engineer successfully gained access to a shell on a Linux host as a standard user and wants to elevate the privilege levels. Which of the following is a valid Linux post-exploitation method to use to accomplish this goal? 

Answer options:

A. Spawn a shell using sudo and an escape string such as sudo vim -c ˜!sh`.
B. Perform ASIC password cracking on the host.
C. Read the /etc/passwd file to extract the usernames.
D. Initiate unquoted service path exploits.
E. Use the UNION operator to extract the database schema.