PT0-002 Attacks and Exploits Practice Question
A tester wants to enumerate SMB shares and execute commands remotely on a Windows target using captured credentials. Which tool is most appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CrackMapExec
CrackMapExec is a versatile tool for SMB enumeration, command execution, and lateral movement with credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat
Why it's wrong here
Hashcat is a specialized password recovery tool that uses GPU acceleration to crack password hashes, including NTLM hashes. It has no ability to interact with SMB shares over a network, nor does it provide any command execution capabilities. Therefore, it is entirely unsuitable for enumerating shares or executing commands on a remote system.
- ✗
Responder
Why it's wrong here
Responder poisons LLMNR, NBT-NS, and mDNS queries on a local network to intercept authentication requests and capture NetNTLMv2 hashes. While these hashes can later be relayed or cracked to gain access, Responder itself cannot enumerate SMB shares or execute commands on a remote host. It is purely a network-level tool for credential capture, not an SMB client or execution framework.
- ✓
CrackMapExec
Why this is correct
CrackMapExec is a post-exploitation tool that natively supports SMB share enumeration and remote command execution. It authenticates over SMB and can list shares, access files, and run arbitrary commands via named pipes or WMI. This makes it the correct choice for a tester who needs to enumerate SMB shares and execute commands in an Active Directory environment.
- ✗
Bettercap
Why it's wrong here
Bettercap is a versatile MITM framework used for network attacks such as ARP spoofing, DNS spoofing, and credential sniffing. Although it can intercept SMB sessions and capture hashes, it lacks built-in functionality for enumerating SMB shares or executing commands on a remote server. Its design centers on network-layer interception and manipulation, not on SMB protocol operations.
Go deeper
Related to this question
Learn chapter
Command and Control (C2) Framework Concepts
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.