PEN-200 Windows Privilege Escalation Practice Question
You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?
⚠ Common exam trap
The trap here is overcomplicating the service start method or assuming a reboot is necessary, when simply starting the service with `sc start` is sufficient and reliable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.
When a service binary is in a writable directory, replacing it with a malicious executable and then starting the service will run the payload as SYSTEM. Because the service is stopped, you can overwrite the file without issues. Using `sc start` is the direct way to trigger execution. Waiting for a reboot is uncertain, and schtasks is for scheduled tasks, not services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace updater.exe and wait for the system to reboot, as services are automatically started on boot.
Why it's wrong here
Waiting for a reboot is unreliable because the service may be set to manual or disabled, and you may not have time. Also, the service is currently stopped, so it might not start automatically. Actively starting the service is the deterministic approach.
- ✗
Replace updater.exe and then use `schtasks /run /tn <servicename>` to trigger the service.
Why it's wrong here
schtasks is for scheduled tasks, not services. Using it to run a service is incorrect; you would use `sc start` or `net start`. This command would fail or target the wrong component, so it does not achieve execution.
- ✓
Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.
Why this is correct
The service executable is run with SYSTEM privileges. By replacing the binary and starting the service, your malicious code executes as SYSTEM. Since the service is stopped, you can overwrite the file and then start it. This is a direct and reliable method.
- ✗
Replace updater.exe and then use `wmic service where name='<servicename>' call startservice`.
Why it's wrong here
While WMIC can start services, it is a more complex method and may require additional permissions. The simpler and more reliable method is `sc start`. WMIC might work, but it is not the most straightforward; also, if the service is stopped, `sc start` is standard.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.