Courseiva

PT0-002 Post-exploitation and Lateral Movement Practice Question

A penetration tester has compromised a Windows host and wants to perform lateral movement using WMI. The tester has obtained local administrator credentials for the target host but wants to avoid writing files to disk. Which two methods can be used to execute commands remotely via WMI without creating files on the target? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any remote execution method is fileless or WMI-based; tools like PsExec and schtasks write to disk, and WinRS uses a different protocol.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using wmic /node:target process call create "cmd.exe /c ..."

Two WMI-based methods for remote command execution without writing files to disk are using the wmic command-line tool with process call create, and using PowerShell's Invoke-WmiMethod to call Win32_Process Create. Both leverage WMI to spawn processes on the target. PsExec writes a service binary to disk, schtasks creates a scheduled task on disk, and WinRS uses WinRM, not WMI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using wmic /node:target process call create "cmd.exe /c ..."

    Why this is correct

    The wmic command-line tool can execute processes on a remote host via WMI. When using process call create, it creates a new process on the target, which runs the specified command. This does not require writing a file to disk on the target, as the command is executed directly. However, it may create temporary files depending on the command, but the WMI mechanism itself does not write a payload to disk. This is a common fileless lateral movement technique.

  • ✗

    Using winrs -r:target cmd.exe

    Why it's wrong here

    WinRS (Windows Remote Shell) uses the WinRM protocol to execute commands remotely. It does not use WMI and does not write files to disk by default. However, the question specifically asks for methods that use WMI. WinRS is a different protocol (WS-Management) and is not WMI-based. Therefore, it is not a correct answer for this scenario, despite being a fileless remote execution method.

  • ✗

    Using schtasks /create /s target /tn ... /tr ... /sc once /st ...

    Why it's wrong here

    The schtasks command creates a scheduled task on the remote host. This involves writing the task definition to disk (in the Task Scheduler database) and may also involve writing a script or executable if the task runs one. While it can execute commands remotely, it is not a WMI method and does write to disk. Therefore, it does not satisfy the requirement of using WMI without writing files.

  • ✓

    Using Invoke-WmiMethod -Class Win32_Process -Name Create -ComputerName target -ArgumentList "cmd.exe /c ..."

    Why this is correct

    The Invoke-WmiMethod PowerShell cmdlet calls the Win32_Process Create method on a remote computer. This executes the specified command without writing any files to the target's disk. The command runs in the context of the WMI provider, and the output can be captured if needed. This is a fileless method for remote command execution via WMI, often used in penetration testing to avoid leaving artifacts on disk.

  • ✗

    Using psexec.exe \\target -accepteula cmd.exe

    Why it's wrong here

    PsExec is a tool that copies a service executable to the ADMIN$ share on the target and creates a service to run it. This writes files to disk, specifically the PSEXESVC.exe file, and creates a service. While it can execute commands remotely, it does not meet the requirement of avoiding disk writes. Therefore, it is not a correct choice for fileless WMI-based lateral movement.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.