PEN-200 Windows Privilege Escalation Practice Question
What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?
⚠ Common exam trap
Candidates often confuse accesschk with credential dumping tools or general vulnerability scanners, failing to recognize its specific utility for auditing resource permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To identify files and services with weak permissions.
Accesschk is a powerful tool from the Sysinternals suite used to check the permissions of files, directories, registry keys, and services. In privilege escalation, it allows an attacker to quickly find misconfigured resources that the current user can modify. By identifying these 'weak' permissions, the attacker can pinpoint specific targets for exploitation, such as replacing a service binary or modifying a sensitive script.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To bypass Windows Firewall rules.
Why it's wrong here
Accesschk is an enumeration tool for file system and object permissions. It has no capability to interact with the Windows Firewall or modify network traffic rules. Attempting to use it for firewall bypass would be ineffective and demonstrates a misunderstanding of the tool's intended use.
- ✓
To identify files and services with weak permissions.
Why this is correct
Accesschk is specifically designed to display the effective permissions for a user or group on various system objects. It is the industry-standard tool for finding files, services, or registry keys that are improperly secured, allowing for targeted privilege escalation attempts on a compromised system.
- ✗
To dump the SAM database for password hashes.
Why it's wrong here
Accesschk is for permission auditing, not password extraction. Dumping the SAM database requires administrative privileges and different specialized tools. Misusing accesschk for this purpose will not yield any password hashes or sensitive authentication data from the system.
- ✗
To automate the deployment of kernel exploits.
Why it's wrong here
Accesschk does not possess the ability to execute or deploy exploits. Its function is strictly to report on the security descriptors of objects. While it helps find the targets for exploits, it is not an exploit delivery or automation framework itself.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.