Courseiva
Exploitation Fundamentals →mediumMultiple Choice

GPEN Exploitation Fundamentals Practice Question

During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?

⚠ Common exam trap

The trap here is assuming that SYSTEM-level access automatically grants access to all resources the logged-on user could reach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.

When psexec runs a payload as a service, the resulting process runs as NT AUTHORITY\SYSTEM. SYSTEM has no user credentials, so it cannot access network resources that require the logged-on user's authentication. To access those resources, the tester must migrate into a process running under the user's context or steal a token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.

    Why this is correct

    SYSTEM has no user credentials, so it cannot authenticate to remote resources that require the logged-on user's token. This is why mapped drives and network shares tied to the interactive user are inaccessible from a SYSTEM-level session unless you migrate or steal a token.

  • ✗

    The psexec module drops the payload into a temporary directory that lacks the necessary permissions to access network shares.

    Why it's wrong here

    The payload's storage location does not determine network share access rights. Access to a mapped drive depends on the security token of the process, not the directory from which the payload runs. The SYSTEM token is the limiting factor here.

  • ✗

    The mapped drive was disconnected when the psexec service was created, and you must re-map it manually from the Meterpreter shell.

    Why it's wrong here

    Creating a service via psexec does not remove existing drive mappings. The mappings still exist in the user's session, but the SYSTEM token cannot use them because it lacks the user's credentials. Re-mapping would not solve the underlying token issue.

  • ✗

    The firewall on the target is blocking SMB traffic from the SYSTEM account, preventing access to the mapped drive.

    Why it's wrong here

    Host firewalls filter by network profile and port, not by user account. SMB traffic from SYSTEM would be treated the same as from any other process. The access denied error is an authentication and authorization issue, not a network filtering one.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.