PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing lateral movement in a Windows domain after compromising a workstation. Which THREE techniques can be used to move to another machine?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil-WinRM
PsExec, WMIExec, and Evil-WinRM are common tools for lateral movement in Windows environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing is a Layer 2 man-in-the-middle (MITM) technique that works by sending forged Address Resolution Protocol replies to poison a victim's ARP cache, redirecting network traffic to the attacker's machine for interception or sniffing. This attack interferes with the data flow between two hosts but does not provide a mechanism for authenticated remote execution or credential reuse against a target system. In a lateral movement context, ARP spoofing is not a viable method because it focuses on network-level manipulation rather than leveraging Windows administrative protocols or services to run commands on another host. Thus, it is incorrect for this scenario.
- ✓
Evil-WinRM
Why this is correct
Evil-WinRM is a purpose-built post-exploitation and lateral movement tool that wraps the WinRM protocol (Windows Remote Management), typically operating over ports 5985/5986, to provide an interactive PowerShell session on a remote Windows host. It authenticates with valid credentials (often obtained via hash, LM, or NTLM pass-the-hash) and is optimized for penetration testing, supporting local and SMB upload/download, script execution, and memory injection. This strongly aligns with lateral movement because it allows an attacker to move from a compromised host to another using standard Windows remote management services, making it a correct answer.
- ✓
WMIExec
Why this is correct
WMIExec, a component of the Impacket suite, executes commands on remote Windows systems by leveraging Windows Management Instrumentation (WMI) over RPC (often port 135). It uses valid credentials (including pass-the-hash) to create and call WMI methods, enabling remote process execution without writing any files to the target's disk—a classic fileless lateral movement technique. Because WMI is a native Windows management service designed for remote execution, WMIExec is a legitimate and effective method for moving laterally within a Windows network, making it a correct answer.
- ✗
SSH with captured credentials
Why it's wrong here
SSH with captured credentials is typically a remote administration method used for Unix/Linux systems rather than a native Windows lateral movement technique. While modern Windows can host OpenSSH, the default Windows infrastructure relies on SMB, WinRM, WMI, and RPC for remote execution, and SSH is rarely enabled or configured in typical enterprise Windows environments. Furthermore, using SSH does not leverage the domain-joined Windows services commonly abused for lateral movement, and although it can execute commands, captured credentials in a Windows landscape are more directly used with tools like PsExec or WinRM. Therefore, it is not the intended method for lateral movement in this Windows-focused scenario.
- ✓
PsExec
Why this is correct
PsExec (from Microsoft Sysinternals) is a classic lateral movement tool that works over SMB, typically using port 445. It copies a small service executable to the target's ADMIN$ share (admin share), creates a remote service via the Service Control Manager, and then executes it, allowing command execution with administrative privileges. This method requires valid administrator credentials (or a pass-the-hash equivalent) and is widely used in penetration tests because it mirrors the behavior of legitimate Windows administration. PsExec is explicitly designed for remote process execution in Windows, making it an accurate and correct choice.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.