Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.
Start practicing
Post-exploitation and Lateral Movement — choose a session length
Free · No account required
Domain overview
This domain covers actions taken after initial access on Windows and Linux targets: credential dumping, privilege escalation, persistence, and moving between hosts. PT0-003 tests these through scenario questions naming real tooling — WMI, PsExec, Mimikatz, Impacket, BloodHound — and asks you to pick the technique that meets a stated constraint such as avoiding disk writes or staying in memory.
Exam objectives
Executing lateral movement over WMI or SMB with Impacket and PsExec-style tooling
Extracting credentials and Kerberos tickets from memory with Mimikatz sekurlsa commands
Enumerating Active Directory attack paths and privilege escalation with BloodHound and SharpHound
Establishing persistence and pivoting through compromised hosts using SSH tunnels, SOCKS proxies, and scheduled tasks
Confusing pass-the-hash, which reuses an NTLM hash, with pass-the-ticket, which reuses a Kerberos ticket and needs no plaintext password.
Choosing a technique that writes a service binary or payload to disk when the scenario explicitly requires fileless or in-memory execution.
Assuming local administrator on one host equals domain admin; local credentials rarely grant rights on other systems without credential reuse or delegation.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?
2A penetration tester has compromised a Windows host and wants to perform lateral movement using WMI. The tester has obtained local administrator credentials for the target host but wants to avoid writing files to disk. Which two methods can be used to execute commands remotely via WMI without creating files on the target? (Choose two.)
Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.
The Courseiva PT0-003 question bank contains 2 questions in the Post-exploitation and Lateral Movement domain, covering the 14% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Post-exploitation and Lateral Movement domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included