PT0-003 · domain
Post-exploitation and Lateral Movement
This domain covers actions taken after initial access on Windows and Linux targets: credential dumping, privilege escalation, persistence, and moving between hosts. PT0-003 tests these through scenario questions naming real tooling — WMI, PsExec, Mimikatz, Impacket, BloodHound — and asks you to pick the technique that meets a stated constraint such as avoiding disk writes or staying in memory.
Focused practice
Practice Post-exploitation and Lateral Movement questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Post-exploitation and Lateral Movement
Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.
Executing lateral movement over WMI or SMB with Impacket and PsExec-style tooling
Extracting credentials and Kerberos tickets from memory with Mimikatz sekurlsa commands
Enumerating Active Directory attack paths and privilege escalation with BloodHound and SharpHound
Establishing persistence and pivoting through compromised hosts using SSH tunnels, SOCKS proxies, and scheduled tasks
Watch out for
Common Post-exploitation and Lateral Movement exam traps
- ▸Confusing pass-the-hash, which reuses an NTLM hash, with pass-the-ticket, which reuses a Kerberos ticket and needs no plaintext password.
- ▸Choosing a technique that writes a service binary or payload to disk when the scenario explicitly requires fileless or in-memory execution.
- ▸Assuming local administrator on one host equals domain admin; local credentials rarely grant rights on other systems without credential reuse or delegation.
Question index
All Post-exploitation and Lateral Movement questions (2)
Click any question to see the full explanation, or start a practice session above.
A penetration tester has compromised a Windows host and wants to perform lateral movement using WMI. The tester has obtained local administrator credentials for the target host but wants to avoid writing files to disk. Which two methods can be used to execute commands remotely via WMI without creating files on the target? (Choose two.)
Hard2A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?
MediumOther domains
All PT0-003 exam domains
Frequently asked questions
- What does the Post-exploitation and Lateral Movement domain cover on the PT0-003 exam?
- Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.
- How many questions are in this domain?
- This page lists all 2 Post-exploitation and Lateral Movement questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Post-exploitation and Lateral Movement questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.