GPEN Escalation and Exploitation Practice Question
You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)
⚠ Common exam trap
Candidates often try to manually inspect every file on the system. They miss the efficiency of using built-in tools like AccessChk or WMI to automate the discovery of common misconfigurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executing AccessChk from the Sysinternals suite to review discretionary access control lists on service executables.
Discovering unquoted service paths and vulnerable file permissions represents a foundational step in local Windows privilege escalation. Penetration testers leverage tools and native commands to locate binaries running with SYSTEM privileges that can be modified or hijacked, allowing arbitrary code execution upon service restart.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Executing AccessChk from the Sysinternals suite to review discretionary access control lists on service executables.
Why this is correct
AccessChk allows efficient command-line auditing of DACLs on files, directories, and services. Identifying weak permissions where standard users hold write or modify rights on service binaries enables successful replacement of legitimate executables with malicious payloads.
- ✗
Querying the root certificate store via PowerShell to check for untrusted root certification authorities.
Why it's wrong here
The root certificate store holds trusted CAs, not file ACLs or service path strings, so it cannot reveal privilege escalation vectors. It is tempting because certificate enumeration is a legitimate hardening check, but it addresses trust configuration rather than the insecure permissions or unquoted service paths the task requires.
- ✓
Using Windows Management Instrumentation to query the Win32_Service class for executable paths containing spaces without quotes.
Why this is correct
Unquoted service paths with spaces cause Windows to search for executable components sequentially from the root directory if quotes are missing. If an attacker places a malicious executable earlier in the search path, the service will execute it with high privileges upon reboot.
- ✗
Inspecting the local security policy database using the auditpol utility to check account lockout thresholds.
Why it's wrong here
Auditpol configures audit policy and account lockout thresholds, which govern logging and authentication behaviour, not filesystem ACLs or service binary paths. It is tempting as a local security enumeration step, but it would be the right choice for auditing policy compliance, not for finding privilege escalation vectors.
- ✗
Reviewing the Active Directory group policy object inheritance tree using the Resultant Set of Policy tool.
Why it's wrong here
Group Policy inheritance determines domain-wide settings, not the local file ACLs or unquoted service paths on this workstation. It is tempting because RSoP reveals security configuration, but it would be correct when troubleshooting domain policy application, not enumerating local privilege escalation vectors.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.