Courseiva

PEN-200 Windows Privilege Escalation Practice Question

Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?

⚠ Common exam trap

Candidates incorrectly assume that a service lacking the 'Interactive' flag is less privileged or cannot be exploited, failing to realize it still runs with full LocalSystem administrative rights.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service is still fully capable of performing administrative actions.

Even without the 'Interactive' flag, a service running as 'LocalSystem' has the highest possible privileges on the local machine. The flag only determines if the service can display a GUI to the logged-in user. Attackers can still interact with these services via command-line exploits or by injecting code into them, making the 'Interactive' flag irrelevant for determining the security risk of the service account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service is immune to DLL hijacking.

    Why it's wrong here

    The 'Interactive' flag has no bearing on DLL loading mechanisms. A service running as SYSTEM is just as vulnerable to DLL hijacking as any other, regardless of its ability to present a GUI to a user. Security posture depends on file permissions, not the interface flag.

  • ✗

    The service cannot be exploited.

    Why it's wrong here

    Any service running as SYSTEM is a potential target for privilege escalation. The 'Interactive' flag is a legacy feature for GUI interaction and does not act as a security control. An attacker does not need a GUI to exploit a service running with administrative privileges.

  • ✓

    The service is still fully capable of performing administrative actions.

    Why this is correct

    The 'LocalSystem' account is inherently privileged. Whether a service is 'interactive' or not only dictates its ability to show a desktop window. The underlying privileges remain the same, meaning an attacker gaining control of the service process still gains full administrative control over the host.

  • ✗

    The service only runs when a user is logged in.

    Why it's wrong here

    Services configured as 'LocalSystem' typically run as part of the background operating system environment and do not depend on an interactive user session. The 'Interactive' flag refers to GUI capability, not the service's run state or dependence on an active login session.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.