Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a PowerShell…

A penetration tester is analyzing a PowerShell script used during an internal test. The script contains the following code block: ```powershell $cred = Get-Credential $session = New-PSSession -ComputerName 'Server01' -Credential $cred Invoke-Command -Session $session -ScriptBlock { Get-ChildItem C:\Secrets.txt } Remove-PSSession $session ``` What is the primary purpose of this script?

⚠ Common exam trap

Test-takers frequently confuse the use of Get-Credential with a brute-force attack, or misinterpret the remote file access as a local privilege escalation, when the script's clear intent is lateral movement via PowerShell remoting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To achieve lateral movement and access a file on a remote server

The script uses Get-Credential to obtain user credentials, creates a remote PowerShell session (PSSession) to Server01 via New-PSSession, and then executes Get-ChildItem C:\Secrets.txt on that remote server using Invoke-Command. This is the classic pattern for lateral movement: authenticating to a remote host and accessing a file stored there, not performing any local privilege escalation or password brute-forcing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To perform a local privilege escalation using stored credentials

    Why it's wrong here

    This option mischaracterizes the script's purpose. Invoke-Command creates a remote PSSession to Server01 via WinRM, so the activity is directed at another host, not the local system. Local privilege escalation would target the local machine's kernel, services, or token privileges, while stored credentials would be pulled from Credential Manager or a saved SecureString—neither of which appears in this script.

  • ✓

    To achieve lateral movement and access a file on a remote server

    Why this is correct

    The script uses Get-Credential to prompt for valid authentication, then Invoke-Command with a ScriptBlock that runs Get-ChildItem against C:\ on Server01. This is classic lateral movement: authenticating to a remote host over PowerShell Remoting (WinRM) and executing commands to access files. It moves the attacker's foothold from the current machine to Server01, rather than raising privileges on the local system.

  • ✗

    To brute-force the password of the user account via 'Get-Credential'

    Why it's wrong here

    Get-Credential simply displays an interactive credential prompt (GUI or console) and returns a single PSCredential object; it does not attempt multiple usernames or passwords. Brute-forcing would require a loop that repeatedly generates credentials and tries them via Invoke-Command, SMB, or RDP, often using tools like Hydra or CrackMapExec. The script contains no iteration, password-guessing logic, or error-handling loop.

  • ✗

    To execute a script from the remote server using the ScriptBlock

    Why it's wrong here

    A ScriptBlock is an inline block of PowerShell code passed to Invoke-Command, not a reference to a script file stored on the remote server. The remote command here is merely Get-ChildItem C:\ to list files, not executing a .ps1 script residing on Server01. To run a script from the remote server, you would use -FilePath with a local path or explicitly invoke a remote script path after copying it to the target.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.