Courseiva
Public Exploits →mediumMultiple Choice

PEN-200 Public Exploits Practice Question

You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?

⚠ Common exam trap

The trap here is assuming the DLL must be copied to the target's filesystem, when the exploit actually forces the Spooler to load it directly from an attacker-controlled SMB share.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Samba share on your Kali machine with anonymous read access that hosts the malicious DLL.

The PrintNightmare PoC abuses the Spooler's driver installation to load a DLL from a UNC path. The attacker must therefore host that DLL on an SMB share reachable by the target, typically with anonymous read access. The other options either target the wrong delivery mechanism or assume capabilities the attacker does not yet possess.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Upload the DLL to C:\Windows\Temp on the target using an existing low-privilege session.

    Why it's wrong here

    Placing the DLL in C:\Windows\Temp does not satisfy the exploit because the Spooler service loads the library from the attacker-specified UNC path, not a local path. The PoC's AddPrinterDriverEx call references a remote share. Uploading locally would only work with a different exploitation technique that the described PoC does not implement.

  • ✗

    Start a Metasploit handler on port 445 to catch the reverse shell from the Spooler service.

    Why it's wrong here

    Port 445 is SMB and cannot serve as a generic reverse-shell listener. The exploit's payload is a DLL executed by the Spooler, which initiates its own callback based on the DLL's logic. Starting a handler on 445 would conflict with SMB services and does not align with how the PrintNightmare PoC delivers its payload.

  • ✓

    Configure a Samba share on your Kali machine with anonymous read access that hosts the malicious DLL.

    Why this is correct

    The PrintNightmare PoC relies on the target loading a DLL from a UNC path over SMB. You must host the DLL on an accessible SMB share (e.g., via impacket-smbserver or Samba) with anonymous read so the target's Spooler service can fetch and load it. Without this share, the exploit has no payload delivery mechanism.

  • ✗

    Disable Windows Defender Real-Time Protection on the target through a registry remoting call.

    Why it's wrong here

    Disabling Defender is neither required nor possible with the described PoC without prior administrative access. The exploit achieves privilege escalation by abusing the Spooler's driver installation, not by evading Defender first. Attempting registry remoting from an unprivileged context would fail and is not a prerequisite step for this attack.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.