Courseiva

PEN-200 Windows Privilege Escalation Practice Question

Exhibit

C:\Users\admin> icacls "C:\Program Files\MyApp\service.exe"
C:\Program Files\MyApp\service.exe NT AUTHORITY\SYSTEM:(F)
BUILTIN\Administrators:(F)
BUILTIN\Users:(M)

Refer to the exhibit. What can you conclude about the security of this service binary?

⚠ Common exam trap

Candidates mistakenly believe that Read permissions are sufficient to compromise a binary, overlooking the requirement for Modify or Write access to replace the file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The binary can be replaced by any local user to achieve privilege escalation.

The icacls output shows that 'BUILTIN\Users' has '(M)' or Modify permissions on the binary. This means a low-privileged user can replace the legitimate service executable with a malicious one. Because services run as SYSTEM, replacing this file allows for immediate privilege escalation upon the next service restart. This is a common misconfiguration where excessive folder or file permissions enable attackers to gain total control over the host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service is vulnerable to a DLL hijacking attack.

    Why it's wrong here

    While the binary is writable, the output specifically shows Modify permissions on the executable file itself, not a vulnerability related to the DLL search order. DLL hijacking would involve replacing a dependency loaded by the binary, which is a different exploitation path than direct binary replacement.

  • ✓

    The binary can be replaced by any local user to achieve privilege escalation.

    Why this is correct

    The '(M)' permission granted to BUILTIN\Users allows any standard user to write to, modify, or delete the file. By replacing the service executable with a malicious payload, the user can ensure that the next time the service starts, the malicious code executes with SYSTEM privileges.

  • ✗

    The service is secure because only SYSTEM and Administrators have full access.

    Why it's wrong here

    The 'BUILTIN\Users:(M)' entry explicitly grants modify access to standard users. This permission level is excessive for a service binary, as it allows non-administrative users to alter the application's behavior. Therefore, the service is not secure and represents a significant security risk for the underlying system.

  • ✗

    The service cannot be stopped by a standard user.

    Why it's wrong here

    Modify permissions usually include the ability to delete or rename the file, but it does not necessarily grant the right to stop or start a service. While you can replace the binary, you might not have the permission to restart the service to trigger the payload immediately.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.