GPEN Exploitation Fundamentals Practice Question
During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?
⚠ Common exam trap
The trap here is assuming that SYSTEM-level access automatically grants access to all resources the logged-on user could reach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.
When psexec runs a payload as a service, the resulting process runs as NT AUTHORITY\SYSTEM. SYSTEM has no user credentials, so it cannot access network resources that require the logged-on user's authentication. To access those resources, the tester must migrate into a process running under the user's context or steal a token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.
Why this is correct
SYSTEM has no user credentials, so it cannot authenticate to remote resources that require the logged-on user's token. This is why mapped drives and network shares tied to the interactive user are inaccessible from a SYSTEM-level session unless you migrate or steal a token.
- ✗
The psexec module drops the payload into a temporary directory that lacks the necessary permissions to access network shares.
Why it's wrong here
The payload's storage location does not determine network share access rights. Access to a mapped drive depends on the security token of the process, not the directory from which the payload runs. The SYSTEM token is the limiting factor here.
- ✗
The mapped drive was disconnected when the psexec service was created, and you must re-map it manually from the Meterpreter shell.
Why it's wrong here
Creating a service via psexec does not remove existing drive mappings. The mappings still exist in the user's session, but the SYSTEM token cannot use them because it lacks the user's credentials. Re-mapping would not solve the underlying token issue.
- ✗
The firewall on the target is blocking SMB traffic from the SYSTEM account, preventing access to the mapped drive.
Why it's wrong here
Host firewalls filter by network profile and port, not by user account. SMB traffic from SYSTEM would be treated the same as from any other process. The access denied error is an authentication and authorization issue, not a network filtering one.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.