PEN-200 Windows Privilege Escalation Practice Question
You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?
⚠ Common exam trap
Candidates attempt to replace the read-only service executable directly, forgetting that directory-level write access enables alternative vectors like DLL hijacking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLL Hijacking.
If the binary is read-only but the directory is writable, you may be able to perform DLL hijacking. Windows applications often look for DLLs in the application directory before searching system folders. By placing a malicious DLL with the same name as a dependency into the application's folder, you can force the application to load your code when it starts, gaining SYSTEM privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploiting the unquoted service path.
Why it's wrong here
The stem specifies the binary directory is writable, but implies the service path itself might be quoted. Unquoted paths are specific to the path string provided to the Service Control Manager, not the directory permissions. If the path is quoted, this method will not work regardless of directory permissions.
- ✓
DLL Hijacking.
Why this is correct
When an application loads a DLL, it searches the application directory first. If you have write access to that directory, you can place a malicious DLL with a matching name. The application will load it instead of the system version, executing your code under the service's context.
- ✗
Modify the service binary directly.
Why it's wrong here
The stem explicitly states the binary is read-only. Even if the directory is writable, a read-only file attribute or restrictive file permissions on the binary itself will prevent a user from overwriting or modifying it, rendering this path ineffective for privilege escalation.
- ✗
Overwriting the service configuration file.
Why it's wrong here
Overwriting a configuration file might change the service behavior, but it rarely leads to arbitrary code execution unless the configuration file itself is an executable script or contains commands that are parsed by the service in a vulnerable way, which is uncommon for standard Windows services.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.