A city asks the tester to spend remaining time only on a CTF-style kernel exploit that depends on rare race conditions, while common local misconfigs remain unreviewed. What should the tester prefer for CPTS-style value?
Select an answer to reveal the explanation.
Short Explanation
Chasing a once-in-a-blue-moon race is like hunting for a unicorn while the back door is unlocked. CPTS-style work pays off when you cover the everyday misconfigs that actually show up in cities—sudo, services, scripts, and permissions.
Full Explanation
Commercial and CPTS-oriented privilege-escalation assessment emphasizes frequently encountered misconfigurations that municipalities can remediate. Extreme CTF-only kernel races may be interesting academically but often deliver poor coverage and high instability risk. Testers should prefer systematic review of common local weaknesses and document residual risk if rare classes are out of scope or impractical. Scope and safety still override curiosity.