PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing a full-scope engagement and needs to identify potential privilege escalation vectors on a Windows system. Which TWO of the following are valid Windows privilege escalation techniques?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unquoted service path exploitation
Unquoted service paths and AlwaysInstallElevated are both valid Windows privilege escalation techniques. Kerberoasting and pass-the-hash are for credential access, not local escalation; SUID/SGID is Linux.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unquoted service path exploitation
Why this is correct
Unquoted service path exploitation occurs when a Windows service binary's path contains spaces but is not enclosed in quotes. When Windows resolves the path, it checks each space-separated segment in turn, so an attacker with write access to an early directory (e.g., C:\Program.exe or C:\Program Files\Sub.exe) can plant a malicious executable that the service will launch with its own high-integrity privileges, typically SYSTEM. This yields arbitrary code execution without needing credentials or exploiting a kernel bug.
- ✗
Pass-the-hash
Why it's wrong here
Pass-the-hash is a lateral movement technique that uses captured NTLM password hashes to authenticate to remote systems on the network, not a local privilege escalation method. It does not elevate privileges on the current compromised host; it simply reuses an already-valid credential (the hash) to access other machines. Since the attacker already has valid credentials, the technique does not turn a standard user into SYSTEM or bypass local access controls.
- ✓
AlwaysInstallElevated registry key abuse
Why this is correct
AlwaysInstallElevated is a Windows Installer policy that, when enabled for both HKLM and HKCU hive keys, elevates any MSI package to SYSTEM privileges during installation. Because the policy is set for all users, a low-privileged attacker can craft a malicious MSI file containing custom actions or commands that run as SYSTEM, allowing them to create a local admin account or execute arbitrary code. This is a classic local privilege escalation vector because it leverages a misconfigured group policy rather than exploiting a service or kernel flaw.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting attacks target Active Directory service accounts by requesting TGS tickets for SPN-linked accounts and cracking them offline to reconstruct plaintext passwords. This is a credential access technique designed to compromise domain service accounts, and it requires network access to a domain controller; it does not elevate privileges on the local host. It enables lateral movement or domain escalation, but it is not a method to go from a low-integrity local user to SYSTEM on the current machine.
- ✗
SUID/SGID binary exploitation
Why it's wrong here
SUID/SGID binary exploitation is a Linux/Unix privilege escalation technique where a binary with setuid/setgid bits runs with the file owner's or group's privileges, allowing an attacker to spawn a shell as root or another user. This mechanism does not exist on Windows; Windows uses access tokens, service permissions, and other ACL-based controls. Therefore, in a Windows-targeted penetration test, this option is invalid and indicates a misunderstanding of platform-specific privilege escalation.
Go deeper
Related to this question
Learn chapter
IDOR and Broken Access Control
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
Key term
Kerberoasting
Kerberoasting is an attack where a hacker steals service account password hashes from Active Directory to crack them offline and gain unauthorized access.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.