Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.
Start practicing
Windows Privilege Escalation — choose a session length
Free · No account required
Domain overview
This domain covers escalating from a low-privilege Windows shell to SYSTEM or Administrator by abusing misconfigured services, registry keys, scheduled tasks, and file permissions. You enumerate with tools like winPEAS, accesschk, and PowerUp, then exploit weak service binaries, unquoted paths, AlwaysInstallElevated, and writable task files.
Exam objectives
Identifying service binary 'Modify' or FILE_WRITE_DATA permissions and restarting the service to execute a replaced payload.
Checking both HKLM and HKCU AlwaysInstallElevated registry values to abuse msiexec elevated MSI installation.
Finding scheduled tasks with writable scripts or binaries running as SYSTEM and a usable trigger.
Enumerating unquoted service paths, weak folder ACLs, and stored credentials with winPEAS, accesschk, and PowerUp.
Replacing a service binary but forgetting the service must be stopped and restarted, or the host rebooted, before the payload runs.
Setting only one AlwaysInstallElevated key; both HKLM and HKCU must be set to 1 for msiexec to install with elevated privileges.
Assuming a writable scheduled task is exploitable without confirming it runs as SYSTEM and has a trigger you can control.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?
2Refer to the exhibit. What can you conclude about the security of this service binary?
3You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?
4What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?
5Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?
6When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?
7Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?
8Refer to the exhibit. What is the primary vulnerability shown here?
9During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?
10When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?
11An attacker gains a low-privilege shell on a Windows 10 machine and discovers a third-party service named 'DataSync'. The attacker notes that the service runs as SYSTEM and they have 'FILE_WRITE_DATA' permissions on the service executable 'C:\Program Files\DataSync\sync.exe'. Which action is the most direct method to escalate privileges to SYSTEM?
12A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?
13During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?
14During enumeration of a Windows host, you run `whoami /priv` and see that the current user has SeImpersonatePrivilege enabled. You have also uploaded a custom executable to C:\Windows\Temp. Which privilege escalation technique is most directly applicable in this situation?
15During a penetration test on a Windows Server 2019 host, you obtain a low-privileged shell as user 'webuser'. You run 'whoami /priv' and observe that the account has SeImpersonatePrivilege enabled. Which exploitation technique is most directly applicable?
16You have a low-privileged shell on a Windows 10 workstation and discover that the folder 'C:\ProgramData\Updater' has weak permissions: the 'Users' group has 'Write' and 'Modify' rights. A scheduled task runs 'C:\ProgramData\Updater\update.exe' every hour as SYSTEM. What is the most reliable way to escalate privileges?
17You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?
18You are attempting to escalate privileges on a Windows target and decide to exploit unquoted service paths. You find a service with the binary path `C:\Program Files\My App\service.exe` and the service is running as LocalSystem. Which condition must be true for this unquoted path to be exploitable?
19You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?
20You have compromised a Windows host and obtained credentials for a low-privileged domain user. You discover that this user has 'GenericWrite' permissions on a computer object in Active Directory. Which attack technique can you use to escalate privileges on that computer?
21You have obtained a low-privileged shell on a Windows Server 2016 machine. While enumerating, you notice that the 'SeImpersonatePrivilege' is enabled for your user account. You also find that the machine is running a service with a named pipe '\\.\pipe\svcctl' that is accessible. Which tool is specifically designed to exploit this privilege to escalate to SYSTEM?
22You are on a Windows 10 machine and discover that the folder 'C:\Temp' has permissions: BUILTIN\Users:(F). You also notice that a scheduled task runs every hour, executing 'C:\Temp\cleanup.exe' as SYSTEM. However, cleanup.exe does not exist in the folder. What is the most effective way to escalate privileges?
23During a Windows privilege escalation assessment, you encounter a service with an unquoted service path: 'C:\Program Files\Vulnerable Service\service.exe'. The service runs as LocalSystem. Which TWO conditions must be true for you to successfully exploit this unquoted service path? (Choose two.)
24You have a low-privileged shell on a Windows Server 2016 host and run `whoami /priv`. The output shows `SeImpersonatePrivilege` enabled. You also notice that the `Print Spooler` service is running. Which technique would most directly allow you to escalate to NT AUTHORITY\SYSTEM?
Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.
The Courseiva PEN-200 question bank contains 24 questions in the Windows Privilege Escalation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows Privilege Escalation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included