nerdexam
CompTIA

PT0-003 · Question #269

A penetration tester obtained a shell on a Windows system. Which of the following would the tester use to gather more information about the host?

The correct answer is C. nltest.exe. nltest.exe (Option C) is correct because it is a command-line utility used to query domain and network information, such as domain controllers, trust relationships, and site configurations - making it highly valuable for a penetration tester performing reconnaissance after…

Submitted by olafpl· Mar 6, 2026Post-exploitation and Lateral Movement

Question

A penetration tester obtained a shell on a Windows system. Which of the following would the tester use to gather more information about the host?

Options

  • Ammc.exe
  • Bicacls.exe
  • Cnltest.exe
  • Dwinver.exe

How the community answered

(48 responses)
  • A
    8% (4)
  • B
    17% (8)
  • C
    71% (34)
  • D
    4% (2)

Explanation

nltest.exe (Option C) is correct because it is a command-line utility used to query domain and network information, such as domain controllers, trust relationships, and site configurations - making it highly valuable for a penetration tester performing reconnaissance after gaining initial access to a Windows system.

Why the others are wrong:

  • mmc.exe (Microsoft Management Console) is a GUI-based administrative tool used to manage system components, not gather host/network intelligence from a shell.
  • icacls.exe is used to view and modify file/folder permissions (ACLs), which is useful for privilege escalation research but doesn't broadly enumerate host or domain information.
  • winver.exe simply displays the Windows version in a graphical dialog box - minimal reconnaissance value and not practical from a shell context.

Memory Tip: Think of nl in nltest as standing for "Network Lookup" - it's the tool penetration testers use to test and enumerate network/domain relationships after landing on a Windows machine. If you're in a shell and want to "phone home" to understand the domain landscape, nltest is your go-to.

Topics

#Windows commands#Post-exploitation#Information gathering#Domain enumeration

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice