PEN-200 Windows Privilege Escalation Practice Question
A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?
⚠ Common exam trap
A common mistake is assuming that any task running as SYSTEM is exploitable. Without the ability to modify the action or the underlying file, the task is secure regardless of its privileges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The task is configured to run under the context of the SYSTEM account or a member of the Administrators group.
Scheduled tasks are a common persistence and escalation vector. For escalation, the task must execute with higher privileges than the current user, typically as SYSTEM or an Administrator. Additionally, the attacker must have the ability to influence what the task executes, either by modifying the executable file, a script it calls, or the task configuration itself to point to a malicious file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The task is configured to run under the context of the SYSTEM account or a member of the Administrators group.
Why this is correct
Privilege escalation requires moving from a lower privilege level to a higher one. If the task runs as the current low-privilege user, executing code through it provides no elevation. Targeting tasks that run as SYSTEM ensures that once the execution path is hijacked, the resulting shell or command will possess maximum system authority.
- ✗
The task must have a trigger set to 'At log on' for any user on the system.
Why it's wrong here
While a 'log on' trigger is a common way for a task to start, it is not a requirement for exploitation. Tasks can be triggered by schedules, system events, or even manually by the user if permissions allow. The trigger only determines when the exploit occurs, not whether the escalation itself is fundamentally possible.
- ✓
The attacker has permissions to modify the binary or script executed by the task, or can rewrite the task's action path.
Why this is correct
Ownership or write access to the task's resources is the actual mechanism of the exploit. Without the ability to change what the task does—either by overwriting the target script or changing the command line arguments—the attacker cannot force the high-privileged task to run their malicious code, regardless of the task's account.
- ✗
The 'Hidden' attribute must be enabled in the task settings to bypass Windows Defender detection.
Why it's wrong here
The 'Hidden' attribute in a scheduled task merely hides the task from the basic UI view in Task Scheduler; it provides no actual security bypass or privilege escalation capability. Windows Defender and other security tools monitor process execution and file integrity regardless of whether the task is marked as hidden in the interface.
- ✗
The task must be part of the default Windows installation rather than a third-party application.
Why it's wrong here
Actually, third-party tasks are often more vulnerable because they are frequently installed with weak file permissions or unquoted paths. Default Windows tasks are generally well-secured and their binaries are protected by TrustedInstaller. Most successful escalations during the OSCP exam involve misconfigured third-party software rather than native Windows components.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.