PT0-002 Attacks and Exploits Practice Question
After gaining a foothold on a Windows server, a tester wants to laterally move to another machine. The tester has obtained NTLM hashes and wants to execute commands remotely. Which tool is specifically designed for remote command execution using hashes via WMI?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
wmiexec
wmiexec.py (from Impacket) allows executing commands via WMI using NTLM hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
evil-winrm
Why it's wrong here
evil-winrm is incorrect because it communicates via WinRM (Windows Remote Management) using the WSMan protocol on ports 5985/5986, providing an interactive PowerShell session. It does not use WMI to execute commands, so even though it supports pass-the-hash authentication, it cannot fulfill a WMI-based execution request.
- ✓
wmiexec
Why this is correct
wmiexec is correct because it is an Impacket tool that leverages WMI (Windows Management Instrumentation) to remotely execute commands on a Windows target. It authenticates via NTLM hashes (pass-the-hash) and triggers a process through the Win32_Process.Create method, all over DCOM on port 135, making it the ideal choice for WMI-based lateral movement.
- ✗
psexec
Why it's wrong here
psexec is not the right tool because it executes remote commands by creating a Windows service on the target, relying on SMB access to the ADMIN$ share and the Service Control Manager (ports 445/139). Although it can use NTLM hashes with certain variants, its operating mechanism is service-based rather than WMI-based, so it doesn't match the specified WMI requirement.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec (CME) is a multi-protocol swiss-army knife that supports SMB, WinRM, WMI, LDAP, MSSQL, and other services for enumeration and lateral movement. While it can execute WMI queries as one of its many features, it is not designed specifically for WMI execution and lacks the focused WMI-native behavior that wmiexec provides, making it an incorrect answer here.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.