PT0-002 Vulnerability Discovery and Analysis Practice Question
Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?
⚠ Common exam trap
A common mix-up: candidates confuse post-exploitation frameworks (Empire) or credential-dumping tools (Invoke-Mimikatz) with the specific script designed for AD enumeration, or they assume Nishang's broad toolkit includes dedicated AD enumeration, when PowerView is the precise answer for querying user accounts and group memberships.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PowerView
PowerView (option D) is a PowerShell script within the PowerSploit framework specifically designed for post-exploitation enumeration of Active Directory. It provides cmdlets like Get-NetUser, Get-NetGroup, and Get-NetComputer to query user accounts, group memberships, and domain trust relationships via LDAP queries, making it the correct choice for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nishang
Why it's wrong here
Nishang is an umbrella collection of many discrete PowerShell scripts for offensive tasks—keyloggers, port scanners, reverse shells, and credential harvesters—rather than a single script. It is a general-purpose toolkit, and while some of its payloads aid post-exploitation, it does not specifically target Active Directory object enumeration. For that purpose, PowerView is the dedicated AD reconnaissance script, so Nishang is not the correct answer.
- ✗
Empire
Why it's wrong here
Empire is a full-featured post-exploitation Command & Control framework with listeners, agents, and module staging, not a standalone PowerShell script. It can execute PowerView or other modules on compromised hosts, but the question asks for the script that performs Active Directory enumeration. Empire would be the umbrella platform that hosts the script, not the enumeration tool itself, making it incorrect.
- ✗
Invoke-Mimikatz
Why it's wrong here
Invoke-Mimikatz is a PowerShell script that wraps Mimikatz functionality to extract plaintext credentials, Kerberos tickets, and NTLM hashes from memory, particularly from LSASS. Its role is credential dumping and stealing authentication material, not querying Active Directory for users, groups, or permissions. Because the correct answer must describe an AD enumeration script, Invoke-Mimikatz fails the technical requirement despite being a common post-exploitation script.
- ✓
PowerView
Why this is correct
PowerView is a PowerShell script—part of the PowerSploit project—that provides a suite of cmdlets for Active Directory reconnaissance, including Get-DomainUser, Get-DomainGroup, Find-DomainAdmin, and Get-DomainACL. It queries LDAP (and sometimes other AD services) to map the domain, identify privileged accounts, and reveal relationships that aid lateral movement. This makes it the standard tool for AD enumeration during post-exploitation, matching the question's intent.
Go deeper
Related to this question
Learn chapter
Post-Exploitation Techniques
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.