Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing a full-scope engagement and needs to identify potential privilege escalation vectors on a Windows system. Which TWO of the following are valid Windows privilege escalation techniques?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unquoted service path exploitation

Unquoted service paths and AlwaysInstallElevated are both valid Windows privilege escalation techniques. Kerberoasting and pass-the-hash are for credential access, not local escalation; SUID/SGID is Linux.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Unquoted service path exploitation

    Why this is correct

    Unquoted service path exploitation occurs when a Windows service binary's path contains spaces but is not enclosed in quotes. When Windows resolves the path, it checks each space-separated segment in turn, so an attacker with write access to an early directory (e.g., C:\Program.exe or C:\Program Files\Sub.exe) can plant a malicious executable that the service will launch with its own high-integrity privileges, typically SYSTEM. This yields arbitrary code execution without needing credentials or exploiting a kernel bug.

  • ✗

    Pass-the-hash

    Why it's wrong here

    Pass-the-hash is a lateral movement technique that uses captured NTLM password hashes to authenticate to remote systems on the network, not a local privilege escalation method. It does not elevate privileges on the current compromised host; it simply reuses an already-valid credential (the hash) to access other machines. Since the attacker already has valid credentials, the technique does not turn a standard user into SYSTEM or bypass local access controls.

  • ✓

    AlwaysInstallElevated registry key abuse

    Why this is correct

    AlwaysInstallElevated is a Windows Installer policy that, when enabled for both HKLM and HKCU hive keys, elevates any MSI package to SYSTEM privileges during installation. Because the policy is set for all users, a low-privileged attacker can craft a malicious MSI file containing custom actions or commands that run as SYSTEM, allowing them to create a local admin account or execute arbitrary code. This is a classic local privilege escalation vector because it leverages a misconfigured group policy rather than exploiting a service or kernel flaw.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting attacks target Active Directory service accounts by requesting TGS tickets for SPN-linked accounts and cracking them offline to reconstruct plaintext passwords. This is a credential access technique designed to compromise domain service accounts, and it requires network access to a domain controller; it does not elevate privileges on the local host. It enables lateral movement or domain escalation, but it is not a method to go from a low-integrity local user to SYSTEM on the current machine.

  • ✗

    SUID/SGID binary exploitation

    Why it's wrong here

    SUID/SGID binary exploitation is a Linux/Unix privilege escalation technique where a binary with setuid/setgid bits runs with the file owner's or group's privileges, allowing an attacker to spawn a shell as root or another user. This mechanism does not exist on Windows; Windows uses access tokens, service permissions, and other ACL-based controls. Therefore, in a Windows-targeted penetration test, this option is invalid and indicates a misunderstanding of platform-specific privilege escalation.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.