PEN-200 Windows Privilege Escalation Practice Question
During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?
⚠ Common exam trap
Candidates often forget that BOTH registry keys must be set to 1. If only one is set, the installation will not run with elevated privileges, and the exploit will fail silently or return an error.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.
The AlwaysInstallElevated policy is a specific Windows feature that allows non-privileged users to run Windows Installer (MSI) packages with SYSTEM privileges. For this to work, the policy must be enabled in both the machine (HKLM) and user (HKCU) registry hives. Attackers can exploit this by crafting a malicious MSI file that executes a command, such as adding a user or opening a reverse shell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use 'certutil' to download and execute a portable executable (EXE) directly.
Why it's wrong here
While 'certutil' is a useful tool for downloading files, it does not interact with the AlwaysInstallElevated policy. The policy specifically applies to the Windows Installer service and MSI packages. Running a standard EXE file will still occur within the context of the current low-privileged user, resulting in no elevation of privileges.
- ✓
Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.
Why this is correct
This is the standard method for exploiting AlwaysInstallElevated. The 'msiexec' utility processes the MSI file, and because the policy is enabled, the Windows Installer service executes the internal scripts or binaries of the MSI as SYSTEM. The flags '/quiet' and '/qn' ensure the installation happens in the background without user interaction.
- ✗
Modify the 'AlwaysInstallElevated' key in HKCU to point to a malicious script instead of '1'.
Why it's wrong here
The 'AlwaysInstallElevated' registry value is a boolean flag (0 or 1), not a path to an executable. Changing it to a script path would invalidate the policy and prevent the exploit from working. The exploitation occurs by providing an MSI file to the installer service, not by modifying the policy value itself.
- ✗
Inject a malicious DLL into the 'msiexec.exe' process while it is running.
Why it's wrong here
Process injection into 'msiexec.exe' would require the attacker to already have significant privileges or for the process to be running at the same integrity level. Furthermore, this is an unnecessarily complex and unstable approach compared to simply running a malicious MSI file, which is the intended way to leverage this misconfiguration.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.