PEN-200 Windows Privilege Escalation Practice Question
During a Windows privilege escalation assessment, you encounter a service with an unquoted service path: 'C:\Program Files\Vulnerable Service\service.exe'. The service runs as LocalSystem. Which TWO conditions must be true for you to successfully exploit this unquoted service path? (Choose two.)
⚠ Common exam trap
The trap here is thinking the service must be automatic or the binary missing; actually, write access to an earlier directory and the ability to trigger execution are the critical factors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
You must be able to restart the service or trigger a system reboot.
To exploit an unquoted service path, you need write access to a directory that Windows searches before the legitimate binary, and you must be able to cause the service to execute (by restarting it or rebooting). The other conditions are not required: the service can be manual, the binary can be present, and you do not need admin rights.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service must be configured to start automatically.
Why it's wrong here
The service does not need to start automatically; it just needs to be started or restarted at some point. Even a manual or triggered start can execute the malicious binary. The key is that the service runs with high privileges and the path is unquoted, not the startup type.
- ✓
You must be able to restart the service or trigger a system reboot.
Why this is correct
After placing the malicious binary, the service must execute it. This requires the service to start or restart. If you cannot restart the service yourself, waiting for a system reboot may also trigger it if the service starts automatically. Without execution, the exploit does not escalate privileges.
- ✓
You must have write permissions to a directory that appears earlier in the path.
Why this is correct
For an unquoted service path exploit, Windows will attempt to execute each space-separated segment as a potential executable. To place a malicious binary, you need write access to one of the directories that Windows will search before reaching the legitimate executable, such as 'C:\Program Files\Vulnerable' or 'C:\Program Files'. Without write access, you cannot plant the binary.
- ✗
The service binary must be missing from its intended location.
Why it's wrong here
The binary does not need to be missing. The unquoted path vulnerability exists because Windows will try to execute binaries from each space-separated segment before the legitimate one. Even if the legitimate binary exists, the malicious one in an earlier path will be executed first if it exists and is writable.
- ✗
You must have administrative privileges to exploit the service.
Why it's wrong here
The point of privilege escalation is to gain administrative privileges, not to already have them. The exploit relies on weak directory permissions that allow a low-privileged user to write to a directory in the path. Requiring admin rights would defeat the purpose.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.