CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

During a penetration test, a tester gains access to a low-privilege web application account. The tester discovers that a scheduled maintenance script running with root/SYSTEM privileges reads a configuration file from a world-writable directory. By replacing that configuration file with malicious content, the tester causes the scheduled script to execute arbitrary code with root privileges. Which concept does this scenario best illustrate?

  1. ALateral movement
  2. BPrivilege escalation
  3. CSession hijacking
  4. DPass-the-hash
Show answer & explanation

Correct answer: B. Privilege escalation

Privilege escalation is gaining a higher level of access than originally authorized, in this case moving from a low-privilege account to root/SYSTEM by exploiting insecure file permissions on a script that runs with elevated rights. Lateral movement instead refers to moving between systems at a similar privilege level, not increasing privilege on the same host.

Why the other options are wrong

  • A. Wrong: lateral movement means moving across systems, not gaining higher privileges on the same one.
  • C. Wrong: session hijacking takes over an authenticated session, not escalate local privileges via file manipulation.
  • D. Wrong: pass-the-hash involves reusing stolen credential hashes, not exploiting file permissions.

Privilege Escalation

The act of exploiting a bug, misconfiguration, or design flaw to gain elevated access to resources beyond what was originally granted.

  • Vertical escalation gains higher privileges (user to admin/root)
  • Horizontal escalation gains access to peer accounts at the same level
  • Common vectors include insecure file permissions, unpatched kernel exploits, and misconfigured services

Memory trick: Climbing the ladder from user to root via a weak rung (bad permissions).

More Threats, Vulnerabilities, and Mitigations questions