Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

After gaining a foothold on a Windows server, a tester wants to laterally move to another machine. The tester has obtained NTLM hashes and wants to execute commands remotely. Which tool is specifically designed for remote command execution using hashes via WMI?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

wmiexec

wmiexec.py (from Impacket) allows executing commands via WMI using NTLM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    evil-winrm

    Why it's wrong here

    evil-winrm is incorrect because it communicates via WinRM (Windows Remote Management) using the WSMan protocol on ports 5985/5986, providing an interactive PowerShell session. It does not use WMI to execute commands, so even though it supports pass-the-hash authentication, it cannot fulfill a WMI-based execution request.

  • ✓

    wmiexec

    Why this is correct

    wmiexec is correct because it is an Impacket tool that leverages WMI (Windows Management Instrumentation) to remotely execute commands on a Windows target. It authenticates via NTLM hashes (pass-the-hash) and triggers a process through the Win32_Process.Create method, all over DCOM on port 135, making it the ideal choice for WMI-based lateral movement.

  • ✗

    psexec

    Why it's wrong here

    psexec is not the right tool because it executes remote commands by creating a Windows service on the target, relying on SMB access to the ADMIN$ share and the Service Control Manager (ports 445/139). Although it can use NTLM hashes with certain variants, its operating mechanism is service-based rather than WMI-based, so it doesn't match the specified WMI requirement.

  • ✗

    CrackMapExec

    Why it's wrong here

    CrackMapExec (CME) is a multi-protocol swiss-army knife that supports SMB, WinRM, WMI, LDAP, MSSQL, and other services for enumeration and lateral movement. While it can execute WMI queries as one of its many features, it is not designed specifically for WMI execution and lacks the focused WMI-native behavior that wmiexec provides, making it an incorrect answer here.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.