Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing lateral movement in a Windows domain after compromising a workstation. Which THREE techniques can be used to move to another machine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evil-WinRM

PsExec, WMIExec, and Evil-WinRM are common tools for lateral movement in Windows environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing is a Layer 2 man-in-the-middle (MITM) technique that works by sending forged Address Resolution Protocol replies to poison a victim's ARP cache, redirecting network traffic to the attacker's machine for interception or sniffing. This attack interferes with the data flow between two hosts but does not provide a mechanism for authenticated remote execution or credential reuse against a target system. In a lateral movement context, ARP spoofing is not a viable method because it focuses on network-level manipulation rather than leveraging Windows administrative protocols or services to run commands on another host. Thus, it is incorrect for this scenario.

  • ✓

    Evil-WinRM

    Why this is correct

    Evil-WinRM is a purpose-built post-exploitation and lateral movement tool that wraps the WinRM protocol (Windows Remote Management), typically operating over ports 5985/5986, to provide an interactive PowerShell session on a remote Windows host. It authenticates with valid credentials (often obtained via hash, LM, or NTLM pass-the-hash) and is optimized for penetration testing, supporting local and SMB upload/download, script execution, and memory injection. This strongly aligns with lateral movement because it allows an attacker to move from a compromised host to another using standard Windows remote management services, making it a correct answer.

  • ✓

    WMIExec

    Why this is correct

    WMIExec, a component of the Impacket suite, executes commands on remote Windows systems by leveraging Windows Management Instrumentation (WMI) over RPC (often port 135). It uses valid credentials (including pass-the-hash) to create and call WMI methods, enabling remote process execution without writing any files to the target's disk—a classic fileless lateral movement technique. Because WMI is a native Windows management service designed for remote execution, WMIExec is a legitimate and effective method for moving laterally within a Windows network, making it a correct answer.

  • ✗

    SSH with captured credentials

    Why it's wrong here

    SSH with captured credentials is typically a remote administration method used for Unix/Linux systems rather than a native Windows lateral movement technique. While modern Windows can host OpenSSH, the default Windows infrastructure relies on SMB, WinRM, WMI, and RPC for remote execution, and SSH is rarely enabled or configured in typical enterprise Windows environments. Furthermore, using SSH does not leverage the domain-joined Windows services commonly abused for lateral movement, and although it can execute commands, captured credentials in a Windows landscape are more directly used with tools like PsExec or WinRM. Therefore, it is not the intended method for lateral movement in this Windows-focused scenario.

  • ✓

    PsExec

    Why this is correct

    PsExec (from Microsoft Sysinternals) is a classic lateral movement tool that works over SMB, typically using port 445. It copies a small service executable to the target's ADMIN$ share (admin share), creates a remote service via the Service Control Manager, and then executes it, allowing command execution with administrative privileges. This method requires valid administrator credentials (or a pass-the-hash equivalent) and is widely used in penetration tests because it mirrors the behavior of legitimate Windows administration. PsExec is explicitly designed for remote process execution in Windows, making it an accurate and correct choice.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.