PT0-002 Attacks and Exploits Practice Question
You have compromised a low-privileged Windows user and want to move laterally to a domain controller. Which THREE techniques could be used for lateral movement if you have valid credentials? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WMIExec
WMIExec (A) is correct because it leverages valid credentials to execute commands remotely over DCOM/WMI (typically via TCP 135 and dynamic RPC ports), enabling lateral movement to a domain controller without needing an interactive logon. Pass-the-Hash with CrackMapExec (C) is correct because it uses captured NTLM hashes with valid credentials to authenticate via SMB (and other protocols), allowing remote command execution and lateral movement across the domain. PsExec (E) is correct because it authenticates with valid credentials over SMB, copies a service binary to ADMIN$, and creates a remote service to execute commands on the target domain controller. Token impersonation with PrintSpoofer (B) is not a lateral movement technique with valid credentials; it is a local privilege escalation method that abuses the SeImpersonate privilege to gain SYSTEM on the already-compromised host. AS-REP roasting (D) is not lateral movement; it is a credential access technique that requests AS-REP messages for accounts without Kerberos pre-authentication to crack their passwords offline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WMIExec
Why this is correct
WMIExec authenticates over DCOM/RPC using valid domain credentials, executing commands remotely via Win32_Process without needing SMB write access or a service install. Against a domain controller, this satisfies the stem's credential-based lateral movement constraint, since the compromised low-privileged user's valid credentials drive the remote execution.
- ✗
Token impersonation with PrintSpoofer
Why it's wrong here
PrintSpoofer exploits SeImpersonatePrivilege to elevate locally on the same host, not to authenticate to a remote domain controller. It is the right tool for privilege escalation from a service account on one machine, which is a different objective from lateral movement using valid credentials.
- ✓
Pass-the-Hash with CrackMapExec
Why this is correct
Pass-the-Hash reuses an NTLM hash from the compromised host to authenticate without knowing the plaintext password. CrackMapExec injects that hash over SMB to execute commands on the domain controller, enabling lateral movement with valid credential material.
- ✗
AS-REP roasting
Why it's wrong here
AS-REP roasting cracks password hashes for accounts lacking pre-authentication; it recovers credentials rather than using already-valid ones to reach a domain controller. It is the correct technique during credential harvesting, not lateral movement once valid credentials are in hand.
- ✓
PsExec
Why this is correct
PsExec authenticates to the target's ADMIN$ share and SMB service using the valid credentials, then deploys and starts a temporary service to execute commands remotely. This satisfies the stem's requirement for credential-based lateral movement to a domain controller, provided the compromised account holds local administrative rights there.
Go deeper
Related to this question
Learn chapter
Command and Control (C2) Framework Concepts
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.