A penetration tester has gained a foothold on a Windows host and wants to escalate privileges by abusing a misconfigured Windows service. Which TWO conditions would allow the tester to escalate privileges by replacing a service binary? (Choose two.)
If the binary a service launches resides in a folder writable by the low-privilege user, the tester can replace or overwrite it with malicious code. When the service restarts, Windows executes the attacker-controlled binary in the service's security context, typically SYSTEM, yielding privilege escalation. The writable path is the core enabling condition for binary replacement.
Why this answer
Binary-replacement escalation requires the tester to influence which executable the service runs. That happens either when the service binary sits in a directory the tester can write to, or when an unquoted path with spaces lets Windows resolve a planted file from a writable earlier directory. Both conditions let attacker code execute in the service's privileged context, while the other options concern unrelated permissions or start settings.
Exam trap
The trap here is assuming any service-related permission or start configuration enables escalation, when binary replacement strictly requires control over the executable file or its path resolution.