Courseiva

PEN-200 Windows Privilege Escalation Practice Question

What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?

⚠ Common exam trap

Candidates often confuse accesschk with credential dumping tools or general vulnerability scanners, failing to recognize its specific utility for auditing resource permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify files and services with weak permissions.

Accesschk is a powerful tool from the Sysinternals suite used to check the permissions of files, directories, registry keys, and services. In privilege escalation, it allows an attacker to quickly find misconfigured resources that the current user can modify. By identifying these 'weak' permissions, the attacker can pinpoint specific targets for exploitation, such as replacing a service binary or modifying a sensitive script.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To bypass Windows Firewall rules.

    Why it's wrong here

    Accesschk is an enumeration tool for file system and object permissions. It has no capability to interact with the Windows Firewall or modify network traffic rules. Attempting to use it for firewall bypass would be ineffective and demonstrates a misunderstanding of the tool's intended use.

  • ✓

    To identify files and services with weak permissions.

    Why this is correct

    Accesschk is specifically designed to display the effective permissions for a user or group on various system objects. It is the industry-standard tool for finding files, services, or registry keys that are improperly secured, allowing for targeted privilege escalation attempts on a compromised system.

  • ✗

    To dump the SAM database for password hashes.

    Why it's wrong here

    Accesschk is for permission auditing, not password extraction. Dumping the SAM database requires administrative privileges and different specialized tools. Misusing accesschk for this purpose will not yield any password hashes or sensitive authentication data from the system.

  • ✗

    To automate the deployment of kernel exploits.

    Why it's wrong here

    Accesschk does not possess the ability to execute or deploy exploits. Its function is strictly to report on the security descriptors of objects. While it helps find the targets for exploits, it is not an exploit delivery or automation framework itself.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.