nerdexam
CompTIA

PT0-002 · Question #8

A penetration tester has obtained shell access to a Windows host and wants to run a specially crafted binary for later execution using the wmic.exe process call create function. Which of the following

Sign in or unlock PT0-002 to reveal the answer and full explanation for question #8. The question stem and answer options stay visible for context.

Post-exploitation and lateral movement

Question

A penetration tester has obtained shell access to a Windows host and wants to run a specially crafted binary for later execution using the wmic.exe process call create function. Which of the following OS or filesystem mechanisms is MOST likely to support this objective?

Options

  • AAlternate data streams
  • BPowerShell modules
  • CMP4 steganography
  • DPsExec

Unlock PT0-002 to see the answer

You've previewed enough free PT0-002 questions. Unlock PT0-002 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Post-exploitation#Windows execution#WMI#PowerShell
Full PT0-002 Practice