PT0-002 › Post-exploitation and Lateral Movement
This domain covers actions taken after initial access on Windows and Linux targets: credential dumping, privilege escalation, persistence, and moving between hosts. PT0-003 tests these through scenario questions naming real tooling — WMI, PsExec, Mimikatz, Impacket, BloodHound — and asks you to pick the technique that meets a stated constraint such as avoiding disk writes or staying in memory.
PT0-002 Post-exploitation and Lateral Movement — All 4 Questions
Every question in this domain with answers and detailed explanations.