PEN-200 Active Directory Attacks Practice Question
You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?
⚠ Common exam trap
The trap here is assuming that write access to a GPO allows direct domain admin escalation, when in fact it enables code execution as SYSTEM on affected machines, which can then be used for further privilege escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the GPO to add a new immediate scheduled task that runs a reverse shell as SYSTEM on all computers in the OU.
With write permissions on a GPO linked to an OU containing privileged servers, modifying the GPO to add an immediate scheduled task that runs as SYSTEM allows code execution with elevated privileges on those servers. This directly escalates privileges by leveraging the GPO's application to all computers in the OU, achieving SYSTEM-level access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the compromised user to add themselves to the Domain Admins group directly via LDAP modification.
Why it's wrong here
Adding oneself to Domain Admins requires permissions to modify the domain's AdminSDHolder or the group itself, which a standard user typically lacks. The scenario specifies write permissions on a GPO, not on the domain object or the Domain Admins group. This approach would fail due to insufficient privileges and is not related to the GPO misconfiguration.
- ✗
Configure a new GPO to deploy a startup script that disables antivirus on all servers in the OU.
Why it's wrong here
While modifying a GPO to deploy a startup script is possible, simply disabling antivirus does not directly escalate privileges. It may aid in further attacks but does not grant elevated access by itself. The goal is to escalate privileges, so a more direct action like adding a scheduled task to run as SYSTEM is preferable. This option is less effective and indirect.
- ✗
Extract the KRBTGT hash using DCSync and forge a Golden Ticket to gain domain admin access.
Why it's wrong here
DCSync requires the Replicating Directory Changes permissions, which the user likely does not have. The scenario only mentions write access to a GPO, not replication rights. While a Golden Ticket would grant domain admin access, it is not feasible here without the necessary permissions or the KRBTGT hash. This option is a non-sequitur to the GPO misconfiguration.
- ✓
Modify the GPO to add a new immediate scheduled task that runs a reverse shell as SYSTEM on all computers in the OU.
Why this is correct
If a user has write permissions on a GPO linked to an OU with privileged servers, they can modify the GPO to include a malicious scheduled task or startup script. This task will execute with SYSTEM privileges on all affected computers when Group Policy refreshes. This is a direct and effective privilege escalation method, as it leverages the GPO's application to gain elevated code execution.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.