Courseiva

PEN-200 Windows Privilege Escalation Practice Question

During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?

⚠ Common exam trap

Candidates often try to replace the original service executable. However, the exploit relies on creating a new, malicious executable that matches the fragmented path segment to hijack the resolution process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.

Placing a malicious executable with a name matching the fragmented path segment allows you to hijack the service binary resolution process when the service restarts. Windows searches for spaces sequentially from left to right, executing your payload with Local System privileges. This technique is a fundamental Windows privilege escalation vector taught in the PEN-200 curriculum.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the Windows Registry ImagePath entry directly using standard user credentials to append your custom payload path.

    Why it's wrong here

    Standard users lack write permissions to the registry keys under HKLM\System\CurrentControlSet\Services where service binary paths are stored. Attempting this modification without administrative privileges results in an access denied error, rendering registry tampering ineffective for unquoted service paths.

  • ✗

    Replace the existing service executable file directly inside the protected system folder to hijack execution upon the next reboot.

    Why it's wrong here

    The directory containing the legitimate service executable lacks write permissions for standard users, preventing direct replacement of the binary. Exploitation relies specifically on directory creation permissions higher up the path tree where spaces cause Windows to misinterpret binary resolution.

  • ✓

    Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.

    Why this is correct

    Overly permissive DACLs on the parent folder allow standard users to create a malicious executable that matches the first space-separated token of the path. When the service starts, Windows executes this malicious binary instead of the intended program because quotes are missing.

  • ✗

    Send a malformed buffer overflow payload directly to the service network port to achieve remote code execution as Local System.

    Why it's wrong here

    Exploiting unquoted service paths relies strictly on local file system permissions and path resolution quirks rather than network-based software vulnerabilities. Software flaws like buffer overflows require dedicated application analysis and are entirely distinct from misconfigured file system access controls.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.