CompTIA
PT0-002 · Question #8
A penetration tester has obtained shell access to a Windows host and wants to run a specially crafted binary for later execution using the wmic.exe process call create function. Which of the following
Sign in or unlock PT0-002 to reveal the answer and full explanation for question #8. The question stem and answer options stay visible for context.
Post-exploitation and lateral movement
Question
A penetration tester has obtained shell access to a Windows host and wants to run a specially crafted binary for later execution using the wmic.exe process call create function. Which of the following OS or filesystem mechanisms is MOST likely to support this objective?
Options
- AAlternate data streams
- BPowerShell modules
- CMP4 steganography
- DPsExec
Unlock PT0-002 to see the answer
You've previewed enough free PT0-002 questions. Unlock PT0-002 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Post-exploitation#Windows execution#WMI#PowerShell