Courseiva

PEN-200 Windows Privilege Escalation Practice Question

You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?

⚠ Common exam trap

The trap here is overcomplicating the service start method or assuming a reboot is necessary, when simply starting the service with `sc start` is sufficient and reliable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.

When a service binary is in a writable directory, replacing it with a malicious executable and then starting the service will run the payload as SYSTEM. Because the service is stopped, you can overwrite the file without issues. Using `sc start` is the direct way to trigger execution. Waiting for a reboot is uncertain, and schtasks is for scheduled tasks, not services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace updater.exe and wait for the system to reboot, as services are automatically started on boot.

    Why it's wrong here

    Waiting for a reboot is unreliable because the service may be set to manual or disabled, and you may not have time. Also, the service is currently stopped, so it might not start automatically. Actively starting the service is the deterministic approach.

  • ✗

    Replace updater.exe and then use `schtasks /run /tn <servicename>` to trigger the service.

    Why it's wrong here

    schtasks is for scheduled tasks, not services. Using it to run a service is incorrect; you would use `sc start` or `net start`. This command would fail or target the wrong component, so it does not achieve execution.

  • ✓

    Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.

    Why this is correct

    The service executable is run with SYSTEM privileges. By replacing the binary and starting the service, your malicious code executes as SYSTEM. Since the service is stopped, you can overwrite the file and then start it. This is a direct and reliable method.

  • ✗

    Replace updater.exe and then use `wmic service where name='<servicename>' call startservice`.

    Why it's wrong here

    While WMIC can start services, it is a more complex method and may require additional permissions. The simpler and more reliable method is `sc start`. WMIC might work, but it is not the most straightforward; also, if the service is stopped, `sc start` is standard.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.