hardMultiple Choice
PT0-002 Practice Question: A penetration tester has gained a low-privileged…
A penetration tester has gained a low-privileged command shell on a Windows 10 system. The tester suspects there is a vulnerable service with an unquoted service path that can be exploited for privilege escalation. Which command should the tester use to identify all services with this vulnerability?
⚠ Common exam trap
Candidates often assume `sc query` or `Get-Service` will reveal the raw unquoted path, but these commands may normalize or omit quotation marks, whereas the registry `ImagePath` value stores the exact string used by the service, including missing quotes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
reg query HKLM\SYSTEM\CurrentControlSet\Services\ /s /v ImagePath
The `reg query` command with the `/s` switch recursively searches the registry key `HKLM\SYSTEM\CurrentControlSet\Services` for the `ImagePath` value of each service. An unquoted service path vulnerability occurs when the `ImagePath` contains spaces and is not enclosed in quotes, allowing an attacker to execute arbitrary code by placing a malicious executable in a path that Windows interprets as a command with arguments. This command directly retrieves the raw path strings from the registry, making it the most reliable method to identify unquoted paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Get-Service | Format-List Name,PathName
Why it's wrong here
PowerShell's Get-Service cmdlet returns ServiceController objects, which expose only Status, Name, DisplayName, and related service-control properties; a PathName property does not exist on this object, so Format-List Name,PathName simply outputs an empty/blank PathName column. To obtain executable paths in PowerShell, an attacker would need to use Get-CimInstance Win32_Service and select Name, PathName, or query the registry directly. This command therefore does not reveal where each service's binary resides.
- ✓
reg query HKLM\SYSTEM\CurrentControlSet\Services\ /s /v ImagePath
Why this is correct
This command recursively enumerates every subkey under the Services registry key and requests the ImagePath value for each service/driver, producing the full command line or binary path that Windows will execute. Because a standard, low-privileged user can read HKLM\SYSTEM (CurrentControlSet), this is a practical enumeration step. An attacker can then identify entries whose paths contain spaces and lack surrounding quotes, setting up an unquoted-service-path privilege escalation attack by placing a crafted executable in a writable directory earlier in the path.
- ✗
sc query type= all state= all | findstr "SERVICE_NAME"
Why it's wrong here
sc query type= all state= all returns a summary of all services (including drivers) with fields such as SERVICE_NAME, DISPLAY_NAME, and STATE, but never includes the binary path or ImagePath. Piping the output through findstr "SERVICE_NAME" merely filters out those summary lines, leaving only the service names, which reveals nothing about executable locations. The similar sc qc <service> command would be needed to query a specific service's BINARY_PATH_NAME, so this pipeline is insufficient for the stated goal.
- ✗
net start
Why it's wrong here
net start lists only the display names of services that are currently running on the machine. It does not show the underlying executable path, nor does it show stopped or disabled services, which are often the targets of unquoted-path or weak-service-permission attacks. A malicious binary might replace a service executable only if the path is writable, and net start gives no information about where such binaries reside.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.