Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

You have compromised a low-privileged Windows user and want to move laterally to a domain controller. Which THREE techniques could be used for lateral movement if you have valid credentials? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WMIExec

WMIExec (A) is correct because it leverages valid credentials to execute commands remotely over DCOM/WMI (typically via TCP 135 and dynamic RPC ports), enabling lateral movement to a domain controller without needing an interactive logon. Pass-the-Hash with CrackMapExec (C) is correct because it uses captured NTLM hashes with valid credentials to authenticate via SMB (and other protocols), allowing remote command execution and lateral movement across the domain. PsExec (E) is correct because it authenticates with valid credentials over SMB, copies a service binary to ADMIN$, and creates a remote service to execute commands on the target domain controller. Token impersonation with PrintSpoofer (B) is not a lateral movement technique with valid credentials; it is a local privilege escalation method that abuses the SeImpersonate privilege to gain SYSTEM on the already-compromised host. AS-REP roasting (D) is not lateral movement; it is a credential access technique that requests AS-REP messages for accounts without Kerberos pre-authentication to crack their passwords offline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WMIExec

    Why this is correct

    WMIExec authenticates over DCOM/RPC using valid domain credentials, executing commands remotely via Win32_Process without needing SMB write access or a service install. Against a domain controller, this satisfies the stem's credential-based lateral movement constraint, since the compromised low-privileged user's valid credentials drive the remote execution.

  • ✗

    Token impersonation with PrintSpoofer

    Why it's wrong here

    PrintSpoofer exploits SeImpersonatePrivilege to elevate locally on the same host, not to authenticate to a remote domain controller. It is the right tool for privilege escalation from a service account on one machine, which is a different objective from lateral movement using valid credentials.

  • ✓

    Pass-the-Hash with CrackMapExec

    Why this is correct

    Pass-the-Hash reuses an NTLM hash from the compromised host to authenticate without knowing the plaintext password. CrackMapExec injects that hash over SMB to execute commands on the domain controller, enabling lateral movement with valid credential material.

  • ✗

    AS-REP roasting

    Why it's wrong here

    AS-REP roasting cracks password hashes for accounts lacking pre-authentication; it recovers credentials rather than using already-valid ones to reach a domain controller. It is the correct technique during credential harvesting, not lateral movement once valid credentials are in hand.

  • ✓

    PsExec

    Why this is correct

    PsExec authenticates to the target's ADMIN$ share and SMB service using the valid credentials, then deploys and starts a temporary service to execute commands remotely. This satisfies the stem's requirement for credential-based lateral movement to a domain controller, provided the compromised account holds local administrative rights there.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.