Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester wants to exploit a Windows service running with SYSTEM privileges that has an unquoted service path containing spaces. Which technique should be used to escalate privileges?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unquoted service path exploitation

An unquoted service path allows placing an executable with the same name as a folder in the path, which Windows will execute with SYSTEM privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AlwaysInstallElevated

    Why it's wrong here

    AlwaysInstallElevated is a Windows registry setting that, when enabled, allows non-privileged users to run MSI packages with elevated (SYSTEM) privileges. This is a valid privilege escalation technique if the user can craft or modify a Windows Installer package, but it does not involve modifying or exploiting the executable path of an existing Windows service. The scenario specifically targets a service running with SYSTEM, so the exploitation vector must be tied to the service's binary path or its loading behavior, not to a separate MSI installation policy.

  • ✗

    Token impersonation

    Why it's wrong here

    Token impersonation is a post-exploitation technique where an attacker uses a stolen or duplicated access token to impersonate a privileged user, often after abusing SeImpersonatePrivilege or exploiting a service to capture a token. It requires an existing token to steal or an interactive service that passes tokens, so it does not directly explain how an attacker would gain code execution by manipulating a service's path. In the context of a vulnerable service binary path, the attacker plants a malicious executable in a directory that the OS will attempt to run due to an unquoted path, which is different from leveraging an already available token.

  • ✓

    Unquoted service path exploitation

    Why this is correct

    An unquoted service path occurs when the ImagePath registry value for a service contains spaces but is not enclosed in quotes. When Windows starts the service, it attempts to locate the executable by splitting the path at each space and trying the resulting filenames, moving from left to right. If an attacker has write access to a directory earlier in that sequence, they can drop a malicious executable (e.g., C:\Program.exe or C:\Program Files\Vendor.exe) that Windows will execute with the service's SYSTEM privileges. This is the correct exploitation method because it directly abuses the service's own path configuration to achieve code execution as SYSTEM.

  • ✗

    DLL hijacking

    Why it's wrong here

    DLL hijacking involves placing a malicious DLL into a location where a legitimate executable will load it, typically by exploiting the Windows DLL search order (e.g., placing a file in the current directory or a system directory). This technique requires the attacker to identify a DLL that the service imports and to have the ability to write to a directory searched by the executable, but it does not rely on the service path being unquoted. Because the scenario explicitly involves a service running with SYSTEM, the most direct exploitation is to replace the service binary or insert a binary into the unquoted path search order, not to hijack a DLL load, which is a separate and more complex attack vector.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.