Courseiva

PEN-200 · topic practice

Windows Privilege Escalation practice questions

This domain covers escalating from a low-privilege Windows shell to SYSTEM or Administrator by abusing misconfigured services, registry keys, scheduled tasks, and file permissions. You enumerate with tools like winPEAS, accesschk, and PowerUp, then exploit weak service binaries, unquoted paths, AlwaysInstallElevated, and writable task files.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Windows Privilege Escalation

What the exam tests

What to know about Windows Privilege Escalation

Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.

Identifying service binary 'Modify' or FILE_WRITE_DATA permissions and restarting the service to execute a replaced payload.

Checking both HKLM and HKCU AlwaysInstallElevated registry values to abuse msiexec elevated MSI installation.

Finding scheduled tasks with writable scripts or binaries running as SYSTEM and a usable trigger.

Enumerating unquoted service paths, weak folder ACLs, and stored credentials with winPEAS, accesschk, and PowerUp.

Watch out for

Common Windows Privilege Escalation exam traps

  • ▸Replacing a service binary but forgetting the service must be stopped and restarted, or the host rebooted, before the payload runs.
  • ▸Setting only one AlwaysInstallElevated key; both HKLM and HKCU must be set to 1 for msiexec to install with elevated privileges.
  • ▸Assuming a writable scheduled task is exploitable without confirming it runs as SYSTEM and has a trigger you can control.

Practice set

Windows Privilege Escalation questions

20 questions · select your answer, then reveal the explanation

You are auditing a machine and find a folder with 'AlwaysInstallElevated' enabled in the registry for both HKLM and HKCU. Which TWO actions allow you to achieve privilege escalation?

Which Windows feature can be abused for privilege escalation if a service is configured to run as a specific user but its password has been changed or retrieved from a configuration file?

Which THREE of the following are common indicators of a potential privilege escalation path via scheduled tasks?

You find a service whose executable is located in a directory where 'Everyone' has 'Full Control'. What is the most significant risk?

Which TWO of the following are effective ways to gather information about potentially vulnerable services?

Which of the following is a classic example of an 'insecure service path' vulnerability?

You have successfully compromised a Windows target and harvested plaintext credentials from memory using a credential dumping tool. Among the retrieved items is a plaintext NTLM hash belonging to a domain administrator account. Which enumeration or attack technique allows you to leverage this hash directly against network services without cracking it?

During a Windows privilege escalation assessment, you successfully identify and abuse a weak service permission to modify a service binary path to launch a reverse shell. However, when you attempt to start the service, the command hangs and the shell fails to spawn. Which THREE common factors could cause a service-based privilege escalation attempt to fail in this manner?

While enumerating a Windows target, you find a service with the following path: C:\Program Files\Custom Tools\Service Monitor\monitor.exe. The path is not enclosed in quotes. You have write access to 'C:\Program Files\Custom Tools\'. What should you name your malicious executable to exploit this vulnerability?

During an internal assessment, you gain a low-privileged shell on a Windows 10 host. Running `whoami /priv` shows that the account has SeImpersonatePrivilege enabled. You want to escalate to SYSTEM by leveraging a tool that abuses this privilege via a named pipe impersonation technique. Which of the following tools is specifically designed to exploit this privilege on modern Windows versions?

You have obtained a low-privileged shell on a Windows Server 2019 machine. During enumeration, you discover that the user account you compromised has the SeBackupPrivilege enabled. You want to leverage this privilege to extract the SAM and SYSTEM registry hives for offline credential extraction. Which of the following commands correctly uses the built-in Windows utility `reg` to save these hives, and what is the required privilege?

During a penetration test on a Windows 10 host, you discover a service named 'DataSync' running as NT AUTHORITY\SYSTEM. The service binary path is 'C:\Program Files\DataSync\syncsvc.exe' and the directory 'C:\Program Files\DataSync' has permissions: BUILTIN\Users:(F). You have a low-privileged shell as user 'bob'. Which action is most likely to yield privilege escalation?

You have obtained a low-privileged shell on a Windows 10 host. Running `whoami /priv` shows that your current token includes SeImpersonatePrivilege. You want to escalate to SYSTEM by leveraging this privilege. Which tool is specifically designed to abuse this privilege by coercing a SYSTEM service to authenticate and then relaying that authentication back to the service?

You have obtained a low-privileged shell on a Windows 10 host. You notice that the `C:\ProgramData` directory contains a subfolder named `Updater` with the following permissions: `BUILTIN\Users:(OI)(CI)(F)`. Inside, there is an executable `update.exe` that is run periodically by a scheduled task under the context of `NT AUTHORITY\SYSTEM`. Which two actions would most likely allow you to escalate privileges? (Choose two.)

During a penetration test, you discover a Windows Server 2016 host where the `AlwaysInstallElevated` policy is enabled in both HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER. You want to escalate privileges to SYSTEM. Which two actions can you take to exploit this misconfiguration? (Choose two.)

You have gained access to a Windows workstation as a standard user. You want to identify installed applications that might have known privilege escalation vulnerabilities. Which command-line tool is specifically designed to list installed software and their versions on a Windows system?

During enumeration on a Windows Server 2016 host, you find that the service 'CustomSvc' runs as LocalSystem and its binary path is 'C:\Program Files\CustomSvc\svc.exe'. The directory 'C:\Program Files\CustomSvc' has default permissions (Administrators: Full Control, SYSTEM: Full Control, Users: Read & Execute). However, you notice that the service has an unquoted path with a space: 'C:\Program Files\CustomSvc\svc.exe'. Which attack is most likely to succeed?

You have gained access to a Windows Server 2019 host as a low-privileged user. You discover that the system has the SeBackupPrivilege and SeRestorePrivilege enabled for your user account. You want to extract the SAM and SYSTEM registry hives to obtain password hashes for offline cracking. Which command should you use to copy the SAM hive to a location where you can access it?

You have a low-privileged shell on a Windows host and want to enumerate potential privilege escalation vectors. Which TWO of the following commands or techniques are effective for discovering weak service permissions? (Choose two.)

You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Windows Privilege Escalation sessions

Start a Windows Privilege Escalation only practice session

Every question in these sessions is drawn from the Windows Privilege Escalation domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Windows Privilege Escalation?
Enumerate service permissions, registry keys, scheduled tasks, and file ACLs, then exploit the weakest misconfiguration to gain SYSTEM. The single most important thing: verify the exact condition (both registry keys, restartable service, SYSTEM-level task) before launching your payload.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Windows Privilege Escalation questions in a focused session?
Yes — the session launcher on this page draws every question from the Windows Privilege Escalation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.