PEN-200 Windows Privilege Escalation Practice Question
When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?
⚠ Common exam trap
Candidates frequently check only the HKLM key, forgetting that the HKCU policy must also be enabled. Both keys are required for the Windows Installer to honor the elevated privilege flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AlwaysInstallElevated value must be set to 1 in HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer.
AlwaysInstallElevated allows low-privileged users to install malicious MSI packages with elevated NT AUTHORITY\SYSTEM privileges. However, exploitation requires both registry hive keys to be properly configured to enabled values. Verifying both keys ensures the Windows Installer service honors the elevated installation flag for all packages regardless of user context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The AlwaysInstallElevated value must be set to 1 in HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer.
Why this is correct
The Windows Installer policy check evaluates both the current user hive and the local machine hive before executing installations. Setting this specific registry key to 1 in the user hive informs the operating system that packages run by this user should receive elevated rights.
- ✓
The AlwaysInstallElevated value must be set to 1 in HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer.
Why this is correct
The system-wide policy hive must also contain the enabled flag to validate the installation behavior across the entire machine. Without both registry locations configured correctly, the Windows Installer service will drop elevation privileges and install the package normally.
- ✗
The local security policy must allow standard users to bypass User Account Control prompts via group policy objects.
Why it's wrong here
Bypassing UAC prompts is unrelated to AlwaysInstallElevated, which instead requires both the HKLM and HKCU registry values set to 1 so Windows Installer runs MSI packages with SYSTEM privileges. UAC bypass techniques matter when a standard user needs elevation without a prompt, not when abusing elevated MSI installation.
- ✗
The target user account must possess local Administrator group membership prior to executing the malicious MSI package.
Why it's wrong here
AlwaysInstallElevated grants SYSTEM-level installation precisely to non-administrative users, so prior Administrator membership defeats the vector's purpose. Requiring admin rights would make the misconfiguration redundant. This condition applies when assessing whether a user can already elevate legitimately, not when weaponising elevated MSI execution.
- ✗
The Task Scheduler service must be configured to permit interactive logons for disabled service accounts.
Why it's wrong here
Task Scheduler interactive logon settings govern scheduled task execution under service accounts, not MSI installation context. AlwaysInstallElevated depends solely on the two registry values under HKLM and HKCU. Task Scheduler configuration becomes relevant when abusing scheduled tasks for persistence or privilege escalation, a separate vector entirely.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.