Post-exploitation and Lateral Movement PT0-003 Practice Quiz
340 exam-style questions covering 14% of the PT0-003 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA PenTest+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Establishing persistence in PenTest+ Objective 5.0 Post-exploitation and Lateral Movement?
- A. Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope.
- B. Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized.
- C. Scheduled tasks run commands or programs at defined times or triggers and can be used to maintain authorized access during testing.
- D. Services run background programs and can be configured or abused for persistence, execution, or privileged activity.
Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope. This is the correct answer.
Which option correctly defines Creating accounts?
- A. Web shells are scripts or files placed on web servers to provide command execution through web requests.
- B. Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized.
- C. Gathering credentials collects passwords, hashes, tokens, keys, tickets, or other authentication material during authorized testing.
- D. Password hashes are one-way representations of passwords that may be cracked or used in certain attacks without knowing the plaintext password.
Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized. This is the correct answer.
A tester has gained initial access and is managing post-exploitation activity involving Establishing persistence. Which choice best describes the concept?
- A. Session cookies should be selected when the post-exploitation or lateral movement scenario matches this purpose: Session cookies store web session identifiers or state and may allow access to a user session if stolen or reused.
- B. Establishing persistence should be selected when the post-exploitation or lateral movement scenario matches this purpose: Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope.
- C. Tokens should be selected when the post-exploitation or lateral movement scenario matches this purpose: Tokens are authentication or authorization artifacts used to prove identity or access rights to services.
- D. SSH keys should be selected when the post-exploitation or lateral movement scenario matches this purpose: SSH keys are cryptographic credentials used to authenticate to SSH services without password entry.
Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope. This matches the post-exploitation or lateral-movement scenario without shifting to a related but different persistence, credential, movement, cleanup, or documentation concept. This is the correct answer.
A tester has gained initial access and is managing post-exploitation activity involving Creating accounts. Which choice best describes the concept?
- A. System enumeration should be selected when the post-exploitation or lateral movement scenario matches this purpose: System enumeration gathers host details such as OS version, hostname, processes, patches, users, privileges, and configuration.
- B. Network enumeration should be selected when the post-exploitation or lateral movement scenario matches this purpose: Network enumeration discovers reachable hosts, routes, services, shares, segments, and trust paths from the compromised position.
- C. Creating accounts should be selected when the post-exploitation or lateral movement scenario matches this purpose: Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized.
- D. Domain enumeration should be selected when the post-exploitation or lateral movement scenario matches this purpose: Domain enumeration gathers directory information such as users, groups, computers, policies, trusts, and privileges.
Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized. This matches the post-exploitation or lateral-movement scenario without shifting to a related but different persistence, credential, movement, cleanup, or documentation concept. This is the correct answer.
A tester has gained initial access and is managing post-exploitation activity involving Scheduled tasks. Which choice best describes the concept?
- A. Impact validation should be selected when the post-exploitation or lateral movement scenario matches this purpose: Impact validation confirms what a compromise could realistically affect, such as access, data exposure, privilege, or business process impact.
- B. Pivoting should be selected when the post-exploitation or lateral movement scenario matches this purpose: Pivoting uses access to one system or network position to reach additional internal systems or segments.
- C. Port forwarding should be selected when the post-exploitation or lateral movement scenario matches this purpose: Port forwarding sends traffic from one host or port through another path to reach systems that are not directly accessible.
- D. Scheduled tasks should be selected when the post-exploitation or lateral movement scenario matches this purpose: Scheduled tasks run commands or programs at defined times or triggers and can be used to maintain authorized access during testing.
Scheduled tasks run commands or programs at defined times or triggers and can be used to maintain authorized access during testing. This matches the post-exploitation or lateral-movement scenario without shifting to a related but different persistence, credential, movement, cleanup, or documentation concept. This is the correct answer.
After initial access, the tester must distinguish persistence, credentials, enumeration, and impact validation. Which scenario best matches Establishing persistence?
- A. A scenario matches Data exfiltration simulation when the tester needs this distinction: Data exfiltration simulation demonstrates how data could be removed or accessed without actually causing unauthorized data loss beyond approved scope.
- B. A scenario matches Impact validation when the tester needs this distinction: Impact validation confirms what a compromise could realistically affect, such as access, data exposure, privilege, or business process impact.
- C. A scenario matches Establishing persistence when the tester needs this distinction: Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope.
- D. A scenario matches Pivoting when the tester needs this distinction: Pivoting uses access to one system or network position to reach additional internal systems or segments.
Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope. This distinction matters because choosing a nearby concept would change the access method, pivot path, Kerberos abuse path, cleanup task, restoration step, or evidence record. This is the correct answer.
After initial access, the tester must distinguish persistence, credentials, enumeration, and impact validation. Which scenario best matches Creating accounts?
- A. A scenario matches SSH tunneling when the tester needs this distinction: SSH tunneling forwards traffic through an SSH connection to reach internal services securely or indirectly.
- B. A scenario matches Remote desktop access when the tester needs this distinction: Remote desktop access provides graphical control of a system and can support post-exploitation interaction when authorized.
- C. A scenario matches Lateral movement when the tester needs this distinction: Lateral movement uses obtained access, credentials, or trust relationships to move from one system to another within the environment.
- D. A scenario matches Creating accounts when the tester needs this distinction: Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized.
Creating accounts adds user or service accounts that can maintain access or support testing goals when authorized. This distinction matters because choosing a nearby concept would change the access method, pivot path, Kerberos abuse path, cleanup task, restoration step, or evidence record. This is the correct answer.
A lead tester must prove impact without leaving uncontrolled access or mishandling credentials. Which answer applies Establishing persistence most accurately?
- A. Remote service execution is the best answer when the access, movement, cleanup, or restoration decision depends on this exact meaning: Remote service execution starts or controls services on another host to execute commands or payloads remotely.
- B. Windows Admin Shares is the best answer when the access, movement, cleanup, or restoration decision depends on this exact meaning: Windows Admin Shares are default administrative SMB shares such as C$ or ADMIN$ that may be used with valid administrative credentials.
- C. PsExec lateral movement is the best answer when the access, movement, cleanup, or restoration decision depends on this exact meaning: PsExec lateral movement uses valid credentials and SMB/service creation to execute commands remotely on Windows systems.
- D. Establishing persistence is the best answer when the access, movement, cleanup, or restoration decision depends on this exact meaning: Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope.
Establishing persistence creates or uses a mechanism that allows continued access after reboots, logouts, or session loss within authorized scope. This applies the concept at the decision point where the wrong term would leave residual access, misrepresent impact, choose the wrong movement path, or fail to restore the environment. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-pentest-plus/post-exploitation-and-lateral-movement/
<a href="https://quizbuffet.com/comptia-pentest-plus/post-exploitation-and-lateral-movement/">CompTIA PenTest+ Post-exploitation and Lateral Movement practice quiz on QuizBuffet</a>
Other PT0-003 Domains
- Engagement Management
- Reconnaissance and Enumeration
- Vulnerability Discovery and Analysis
- Attacks and Exploits
← Back to PT0-003 practice test overview
Questions are written against the published PT0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.