Courseiva

GPEN Domain Escalation and Persistence Practice Question

During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?

⚠ Common exam trap

Candidates often try to modify the existing service binary. They forget that the vulnerability relies on the path resolution order, requiring the placement of a new file, not modification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place a malicious binary at the first detected space-delimited path segment.

Unquoted service paths exist when the service binary path contains spaces and lacks quotes. Windows interprets the path incorrectly, searching for intermediate executables. Placing a malicious binary at the identified path allows it to execute with SYSTEM privileges upon service restart. This technique is critical for privilege escalation as it exploits inherent Windows path resolution logic, often bypassing standard user restrictions if the directory has weak permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Overwrite the existing service executable with a custom payload.

    Why it's wrong here

    Overwriting the actual binary requires administrative permissions that you do not yet possess. If you had permissions to modify the existing binary, you would already have achieved execution, rendering the unquoted path vulnerability irrelevant. This action is usually blocked by standard NTFS access control lists on system directories.

  • ✗

    Modify the service configuration using the sc config command.

    Why it's wrong here

    Changing the service configuration via sc config requires elevated administrative privileges. Since the goal is to escalate privileges, you cannot rely on commands that already require the level of access you are attempting to obtain. This approach is ineffective for a standard user account seeking privilege escalation.

  • ✓

    Place a malicious binary at the first detected space-delimited path segment.

    Why this is correct

    Windows attempts to execute the path segment before the space if no quotes are present. By placing a malicious executable at that specific location with the appropriate name, the service manager will execute your file instead of the intended one, running your code with the service's high-privilege context.

  • ✗

    Inject a DLL into the running service process memory space.

    Why it's wrong here

    Process injection via DLL injection typically requires administrative rights or SeDebugPrivilege to attach to a high-privilege service process. While effective for persistence or credential dumping, it does not leverage the unquoted service path vulnerability itself and is generally restricted for unprivileged users on modern Windows operating systems.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.