Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?

⚠ Common exam trap

A common mix-up: candidates confuse post-exploitation frameworks (Empire) or credential-dumping tools (Invoke-Mimikatz) with the specific script designed for AD enumeration, or they assume Nishang's broad toolkit includes dedicated AD enumeration, when PowerView is the precise answer for querying user accounts and group memberships.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PowerView

PowerView (option D) is a PowerShell script within the PowerSploit framework specifically designed for post-exploitation enumeration of Active Directory. It provides cmdlets like Get-NetUser, Get-NetGroup, and Get-NetComputer to query user accounts, group memberships, and domain trust relationships via LDAP queries, making it the correct choice for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nishang

    Why it's wrong here

    Nishang is an umbrella collection of many discrete PowerShell scripts for offensive tasks—keyloggers, port scanners, reverse shells, and credential harvesters—rather than a single script. It is a general-purpose toolkit, and while some of its payloads aid post-exploitation, it does not specifically target Active Directory object enumeration. For that purpose, PowerView is the dedicated AD reconnaissance script, so Nishang is not the correct answer.

  • ✗

    Empire

    Why it's wrong here

    Empire is a full-featured post-exploitation Command & Control framework with listeners, agents, and module staging, not a standalone PowerShell script. It can execute PowerView or other modules on compromised hosts, but the question asks for the script that performs Active Directory enumeration. Empire would be the umbrella platform that hosts the script, not the enumeration tool itself, making it incorrect.

  • ✗

    Invoke-Mimikatz

    Why it's wrong here

    Invoke-Mimikatz is a PowerShell script that wraps Mimikatz functionality to extract plaintext credentials, Kerberos tickets, and NTLM hashes from memory, particularly from LSASS. Its role is credential dumping and stealing authentication material, not querying Active Directory for users, groups, or permissions. Because the correct answer must describe an AD enumeration script, Invoke-Mimikatz fails the technical requirement despite being a common post-exploitation script.

  • ✓

    PowerView

    Why this is correct

    PowerView is a PowerShell script—part of the PowerSploit project—that provides a suite of cmdlets for Active Directory reconnaissance, including Get-DomainUser, Get-DomainGroup, Find-DomainAdmin, and Get-DomainACL. It queries LDAP (and sometimes other AD services) to map the domain, identify privileged accounts, and reveal relationships that aid lateral movement. This makes it the standard tool for AD enumeration during post-exploitation, matching the question's intent.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.