hardMultiple Choice
PT0-002 Practice Question: A penetration tester discovers a remote command…
A penetration tester discovers a remote command injection vulnerability in a Java-based web application on a Windows server. The tester wants to execute a PowerShell reverse shell. Which encoding technique is most effective to avoid filter restrictions on special characters?
⚠ Common exam trap
It's easy for candidates to choose URL encoding because it is familiar from web attacks, but they overlook that PowerShell's `-EncodedCommand` parameter is specifically designed for Base64, making it the most direct and filter-evading method for remote command injection on Windows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Base64 encoding
Base64 encoding is the most effective technique because it allows the tester to encode the entire PowerShell command, including special characters like semicolons, pipes, and quotes, into a safe ASCII string that bypasses filter restrictions. PowerShell natively supports the `-EncodedCommand` parameter, which decodes Base64 input directly, making it ideal for remote command injection scenarios where character filtering is strict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Base64 encoding
Why this is correct
PowerShell natively supports Base64-encoded commands via the `-EncodedCommand` parameter, which takes a UTF-16LE Base64 string, decodes it, and executes the resulting command. This allows an attacker to transmit a fully obfuscated payload that evades filters that scan for suspicious keywords or special characters like semicolons or brackets, because the entire command is encoded. The encoding is transparent to PowerShell, so no additional decode step is needed, making it a reliable bypass in command injection scenarios.
- ✗
URL encoding
Why it's wrong here
URL encoding (percent-encoding) only transforms characters for safe transmission in HTTP URLs, such as encoding `;` as `%3B`. Most web servers and application frameworks automatically decode URL-encoded data before passing it to the backend, so the application receives the original payload with the decoded semicolon, and any command injection filter sees the same dangerous characters it would have blocked. It does not obscure the payload from the application; it merely changes the wire format, so it cannot bypass server-side filtering that inspects the decoded input.
- ✗
Unicode encoding
Why it's wrong here
Unicode encoding schemes, such as UTF-16 with escape sequences like `\u0069`, represent characters using alternate code points, but PowerShell does not automatically interpret such sequences as executable code in a command string. While some ancillary libraries or scripting parsers might decode Unicode escapes, PowerShell's command invocation path does not, so a Unicode-encoded payload would remain inert unless explicitly converted to a string by additional code. Moreover, many input filters normalize Unicode variations, so the technique is neither a native executable format nor an effective obfuscation method.
- ✗
Hex encoding
Why it's wrong here
Hex encoding (e.g., representing bytes as `0x6A` or `\x6A`) is commonly used for transmitting binary data, but PowerShell has no native feature that executes a hex-encoded string as a command. To execute a hex-encoded payload, an attacker must first explicitly decode it using PowerShell methods like `[Convert]::FromHexString` or by piping the raw bytes into an executable, which adds noticeable extra logic that command injection filters can detect. Because the decoding step is separate and visible, hex encoding does not provide a straightforward or stealthy bypass.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Command injection
Command injection is a security vulnerability where an attacker inserts malicious commands into a system through an input field, tricking the application into executing them on the underlying operating system.
Key term
Reverse shell
A reverse shell is a type of remote access attack where the target machine initiates an outbound connection back to the attacker, allowing the attacker to execute commands on the compromised system.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.