Courseiva

PEN-200 Windows Privilege Escalation Practice Question

During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?

⚠ Common exam trap

Candidates often forget that BOTH registry keys must be set to 1. If only one is set, the installation will not run with elevated privileges, and the exploit will fail silently or return an error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.

The AlwaysInstallElevated policy is a specific Windows feature that allows non-privileged users to run Windows Installer (MSI) packages with SYSTEM privileges. For this to work, the policy must be enabled in both the machine (HKLM) and user (HKCU) registry hives. Attackers can exploit this by crafting a malicious MSI file that executes a command, such as adding a user or opening a reverse shell.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use 'certutil' to download and execute a portable executable (EXE) directly.

    Why it's wrong here

    While 'certutil' is a useful tool for downloading files, it does not interact with the AlwaysInstallElevated policy. The policy specifically applies to the Windows Installer service and MSI packages. Running a standard EXE file will still occur within the context of the current low-privileged user, resulting in no elevation of privileges.

  • ✓

    Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.

    Why this is correct

    This is the standard method for exploiting AlwaysInstallElevated. The 'msiexec' utility processes the MSI file, and because the policy is enabled, the Windows Installer service executes the internal scripts or binaries of the MSI as SYSTEM. The flags '/quiet' and '/qn' ensure the installation happens in the background without user interaction.

  • ✗

    Modify the 'AlwaysInstallElevated' key in HKCU to point to a malicious script instead of '1'.

    Why it's wrong here

    The 'AlwaysInstallElevated' registry value is a boolean flag (0 or 1), not a path to an executable. Changing it to a script path would invalidate the policy and prevent the exploit from working. The exploitation occurs by providing an MSI file to the installer service, not by modifying the policy value itself.

  • ✗

    Inject a malicious DLL into the 'msiexec.exe' process while it is running.

    Why it's wrong here

    Process injection into 'msiexec.exe' would require the attacker to already have significant privileges or for the process to be running at the same integrity level. Furthermore, this is an unnecessarily complex and unstable approach compared to simply running a malicious MSI file, which is the intended way to leverage this misconfiguration.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.