Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges by abusing a misconfigured Windows service. Which TWO conditions would allow the tester to escalate privileges by replacing a service binary? (Choose two.)

⚠ Common exam trap

The trap here is assuming any service-related permission or start configuration enables escalation, when binary replacement strictly requires control over the executable file or its path resolution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service's executable path points to a directory where the tester has write permissions

Binary-replacement escalation requires the tester to influence which executable the service runs. That happens either when the service binary sits in a directory the tester can write to, or when an unquoted path with spaces lets Windows resolve a planted file from a writable earlier directory. Both conditions let attacker code execute in the service's privileged context, while the other options concern unrelated permissions or start settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service is configured with a delayed automatic start type on a domain-joined host

    Why it's wrong here

    A delayed automatic start type only affects when the service launches after boot; it conveys no permission over the binary or its directory. The start type does not grant the tester any ability to modify files. Escalation via binary replacement depends on write access or path resolution flaws, neither of which is provided by the start configuration described here.

  • ✗

    The service runs under the NetworkService account with SeShutdownPrivilege enabled

    Why it's wrong here

    Running as NetworkService with SeShutdownPrivilege does not by itself permit binary replacement. That privilege only allows shutting down the local system and does not grant write access to service binaries or their directories. Without a writable path or an unquoted-path weakness, the tester cannot substitute the executable, so this condition does not enable escalation.

  • ✗

    The service's DACL grants the tester SERVICE_STOP and SERVICE_START but not SERVICE_CHANGE_CONFIG

    Why it's wrong here

    Permissions to stop and start a service let the tester control its lifecycle but not modify its configuration or its binary. Without the ability to change the executable path or write to the referenced file, restarting the service only re-runs the legitimate binary. This permission set alone does not create a binary-replacement escalation path.

  • ✓

    The service's executable path points to a directory where the tester has write permissions

    Why this is correct

    If the binary a service launches resides in a folder writable by the low-privilege user, the tester can replace or overwrite it with malicious code. When the service restarts, Windows executes the attacker-controlled binary in the service's security context, typically SYSTEM, yielding privilege escalation. The writable path is the core enabling condition for binary replacement.

  • ✓

    The service's unquoted path contains a space and an earlier directory in the path is writable

    Why this is correct

    An unquoted service path containing spaces causes Windows to try candidate executables in each directory sequentially. If the tester can write to one of those earlier directories, the tester can plant a malicious executable with a matching name. When the service starts, Windows resolves and runs the planted file before the intended binary, escalating privileges.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.