PEN-200 Windows Privilege Escalation Practice Question
You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?
⚠ Common exam trap
The trap here is thinking that AlwaysInstallElevated allows arbitrary executables to run elevated, when it specifically applies to MSI packages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a malicious MSI package and execute it with `msiexec /quiet /qn /i malicious.msi` to run with SYSTEM privileges.
With AlwaysInstallElevated enabled in both registry hives, any MSI package installed by a user runs with SYSTEM privileges. The most direct exploitation is to create a malicious MSI that performs a privileged action, such as adding a user to the Administrators group, and then install it using `msiexec`. This leverages the misconfiguration exactly as designed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Leverage the setting to bypass UAC and run any executable as an administrator without an MSI package.
Why it's wrong here
AlwaysInstallElevated does not bypass UAC for arbitrary executables; it only elevates MSI installations. UAC bypass techniques are separate and typically involve other mechanisms. This setting cannot be used to directly run a standalone executable with elevated privileges.
- ✓
Create a malicious MSI package and execute it with `msiexec /quiet /qn /i malicious.msi` to run with SYSTEM privileges.
Why this is correct
When AlwaysInstallElevated is enabled in both HKLM and HKCU, any MSI package installed by the user runs with elevated (SYSTEM) privileges. You can generate a malicious MSI that executes a command, for example adding a user to the Administrators group, and then install it using `msiexec` with quiet flags to avoid user interaction.
- ✗
Use `reg add` to modify the service binary path of a running service to point to a malicious executable.
Why it's wrong here
Modifying service binary paths requires administrative privileges or write access to the service configuration, neither of which is granted by AlwaysInstallElevated. This setting specifically affects MSI installation behavior, not service configurations, so this approach is unrelated and would likely fail.
- ✗
Extract the MSI to a writable directory and replace a DLL to achieve privilege escalation.
Why it's wrong here
While MSI packages can contain DLLs, the AlwaysInstallElevated setting does not inherently involve DLL hijacking. The direct exploitation is to run a malicious MSI, not to extract and replace files. This method adds unnecessary complexity and does not leverage the setting as intended.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.