PEN-200 · domain
Windows Privilege Escalation
This domain covers escalating from a low-privilege Windows shell to SYSTEM or Administrator by abusing misconfigured services, registry keys, scheduled tasks, and file permissions. You enumerate with tools like winPEAS, accesschk, and PowerUp, then exploit weak service binaries, unquoted paths, AlwaysInstallElevated, and writable task files.
Focused practice
Practice Windows Privilege Escalation questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Privilege Escalation
Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.
Identifying service binary 'Modify' or FILE_WRITE_DATA permissions and restarting the service to execute a replaced payload.
Checking both HKLM and HKCU AlwaysInstallElevated registry values to abuse msiexec elevated MSI installation.
Finding scheduled tasks with writable scripts or binaries running as SYSTEM and a usable trigger.
Enumerating unquoted service paths, weak folder ACLs, and stored credentials with winPEAS, accesschk, and PowerUp.
Watch out for
Common Windows Privilege Escalation exam traps
- ▸Replacing a service binary but forgetting the service must be stopped and restarted, or the host rebooted, before the payload runs.
- ▸Setting only one AlwaysInstallElevated key; both HKLM and HKCU must be set to 1 for msiexec to install with elevated privileges.
- ▸Assuming a writable scheduled task is exploitable without confirming it runs as SYSTEM and has a trigger you can control.
Question index
All Windows Privilege Escalation questions (24)
Click any question to see the full explanation, or start a practice session above.
When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?
Hard2A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?
Hard3Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?
Hard4During a penetration test on a Windows Server 2019 host, you obtain a low-privileged shell as user 'webuser'. You run 'whoami /priv' and observe that the account has SeImpersonatePrivilege enabled. Which exploitation technique is most directly applicable?
Easy5You have obtained a low-privileged shell on a Windows Server 2016 machine. While enumerating, you notice that the 'SeImpersonatePrivilege' is enabled for your user account. You also find that the machine is running a service with a named pipe '\\.\pipe\svcctl' that is accessible. Which tool is specifically designed to exploit this privilege to escalate to SYSTEM?
Hard6You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?
Medium7During a Windows privilege escalation assessment, you encounter a service with an unquoted service path: 'C:\Program Files\Vulnerable Service\service.exe'. The service runs as LocalSystem. Which TWO conditions must be true for you to successfully exploit this unquoted service path? (Choose two.)
Hard8During enumeration of a Windows host, you run `whoami /priv` and see that the current user has SeImpersonatePrivilege enabled. You have also uploaded a custom executable to C:\Windows\Temp. Which privilege escalation technique is most directly applicable in this situation?
Medium9What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?
Easy10You have a low-privileged shell on a Windows 10 workstation and discover that the folder 'C:\ProgramData\Updater' has weak permissions: the 'Users' group has 'Write' and 'Modify' rights. A scheduled task runs 'C:\ProgramData\Updater\update.exe' every hour as SYSTEM. What is the most reliable way to escalate privileges?
Medium11Refer to the exhibit. What is the primary vulnerability shown here?
Medium12You have compromised a Windows host and obtained credentials for a low-privileged domain user. You discover that this user has 'GenericWrite' permissions on a computer object in Active Directory. Which attack technique can you use to escalate privileges on that computer?
Medium13You have a low-privileged shell on a Windows Server 2016 host and run `whoami /priv`. The output shows `SeImpersonatePrivilege` enabled. You also notice that the `Print Spooler` service is running. Which technique would most directly allow you to escalate to NT AUTHORITY\SYSTEM?
Medium14During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?
Medium15Refer to the exhibit. What can you conclude about the security of this service binary?
Medium16You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?
Hard17You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?
Hard18You are on a Windows 10 machine and discover that the folder 'C:\Temp' has permissions: BUILTIN\Users:(F). You also notice that a scheduled task runs every hour, executing 'C:\Temp\cleanup.exe' as SYSTEM. However, cleanup.exe does not exist in the folder. What is the most effective way to escalate privileges?
Medium19When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?
Medium20You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?
Medium21An attacker gains a low-privilege shell on a Windows 10 machine and discovers a third-party service named 'DataSync'. The attacker notes that the service runs as SYSTEM and they have 'FILE_WRITE_DATA' permissions on the service executable 'C:\Program Files\DataSync\sync.exe'. Which action is the most direct method to escalate privileges to SYSTEM?
Medium22You are attempting to escalate privileges on a Windows target and decide to exploit unquoted service paths. You find a service with the binary path `C:\Program Files\My App\service.exe` and the service is running as LocalSystem. Which condition must be true for this unquoted path to be exploitable?
Medium23During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?
Medium24Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?
MediumOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Windows Privilege Escalation domain cover on the PEN-200 exam?
- Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.
- How many questions are in this domain?
- This page lists all 24 Windows Privilege Escalation questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Privilege Escalation questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.