Courseiva

PT0-003 · domain

Post-exploitation and Lateral Movement

This domain covers actions taken after initial access on Windows and Linux targets: credential dumping, privilege escalation, persistence, and moving between hosts. PT0-003 tests these through scenario questions naming real tooling — WMI, PsExec, Mimikatz, Impacket, BloodHound — and asks you to pick the technique that meets a stated constraint such as avoiding disk writes or staying in memory.

2 questions1 medium1 hard

Focused practice

Practice Post-exploitation and Lateral Movement questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Post-exploitation and Lateral Movement

Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.

Executing lateral movement over WMI or SMB with Impacket and PsExec-style tooling

Extracting credentials and Kerberos tickets from memory with Mimikatz sekurlsa commands

Enumerating Active Directory attack paths and privilege escalation with BloodHound and SharpHound

Establishing persistence and pivoting through compromised hosts using SSH tunnels, SOCKS proxies, and scheduled tasks

Watch out for

Common Post-exploitation and Lateral Movement exam traps

  • ▸Confusing pass-the-hash, which reuses an NTLM hash, with pass-the-ticket, which reuses a Kerberos ticket and needs no plaintext password.
  • ▸Choosing a technique that writes a service binary or payload to disk when the scenario explicitly requires fileless or in-memory execution.
  • ▸Assuming local administrator on one host equals domain admin; local credentials rarely grant rights on other systems without credential reuse or delegation.

Frequently asked questions

What does the Post-exploitation and Lateral Movement domain cover on the PT0-003 exam?
Be able to select the right post-exploitation technique for a stated constraint: which tool dumps credentials or tickets, which method moves laterally without touching disk, and which artifact gives persistence. The single most important thing is matching the technique to the constraint, not naming the most powerful tool.
How many questions are in this domain?
This page lists all 2 Post-exploitation and Lateral Movement questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Post-exploitation and Lateral Movement questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
pentest-plus PENTEST-PLUS post exploitation and lateral movement Practice Questions