PEN-200 Windows Privilege Escalation Practice Question
During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?
⚠ Common exam trap
Candidates often try to replace the original service executable. However, the exploit relies on creating a new, malicious executable that matches the fragmented path segment to hijack the resolution process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.
Placing a malicious executable with a name matching the fragmented path segment allows you to hijack the service binary resolution process when the service restarts. Windows searches for spaces sequentially from left to right, executing your payload with Local System privileges. This technique is a fundamental Windows privilege escalation vector taught in the PEN-200 curriculum.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the Windows Registry ImagePath entry directly using standard user credentials to append your custom payload path.
Why it's wrong here
Standard users lack write permissions to the registry keys under HKLM\System\CurrentControlSet\Services where service binary paths are stored. Attempting this modification without administrative privileges results in an access denied error, rendering registry tampering ineffective for unquoted service paths.
- ✗
Replace the existing service executable file directly inside the protected system folder to hijack execution upon the next reboot.
Why it's wrong here
The directory containing the legitimate service executable lacks write permissions for standard users, preventing direct replacement of the binary. Exploitation relies specifically on directory creation permissions higher up the path tree where spaces cause Windows to misinterpret binary resolution.
- ✓
Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.
Why this is correct
Overly permissive DACLs on the parent folder allow standard users to create a malicious executable that matches the first space-separated token of the path. When the service starts, Windows executes this malicious binary instead of the intended program because quotes are missing.
- ✗
Send a malformed buffer overflow payload directly to the service network port to achieve remote code execution as Local System.
Why it's wrong here
Exploiting unquoted service paths relies strictly on local file system permissions and path resolution quirks rather than network-based software vulnerabilities. Software flaws like buffer overflows require dedicated application analysis and are entirely distinct from misconfigured file system access controls.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.