Windows Privilege Escalation

← all quizzes

Answer all 15 questions, then submit. You need 75% to pass. If you don't pass, the reattempt unlocks after 24 hours.

Q1. Meterpreter's `getsystem` typically becomes SYSTEM via:
Q2. SeImpersonatePrivilege is most famously abused by which family of exploits to become SYSTEM?
Q3. DLL hijacking (search-order abuse) works when a privileged program:
Q4. Unattended-install artifacts (unattend.xml, sysprep.inf, autounattend.xml) often contain:
Q5. winPEAS, PowerUp and Seatbelt are used to:
Q6. A writable startup-folder entry or Run key belonging to a higher-priv user lets an attacker:
Q7. PowerShell console history and transcript logs are worth checking because they can leak:
Q8. Dumping LSASS memory (e.g., via comsvcs.dll MiniDump or Task Manager) is done to:
Q9. AlwaysInstallElevated allows any user to install an MSI as SYSTEM only when the value is set:
Q10. SeDebugPrivilege primarily allows an attacker to:
Q11. Token impersonation (e.g., Incognito) abuses:
Q12. A scheduled task that runs as SYSTEM is exploitable for privesc when:
Q13. Windows autologon can leak a cleartext password stored where?
Q14. A directory the attacker can write to that appears EARLY in the system PATH enables:
Q15. A UAC bypass (e.g., fodhelper/eventvwr) is best described as: