Post-Exploitation and Lateral Movement

Worth 14% of the CompTIA PenTest+ (PT0-003) exam. CertClue has 44 questions on this objective.

What this objective covers

Post-Exploitation, Persistence, and Lateral Movement

Gaining initial access is rarely the actual goal of an engagement. The post-exploitation domain covers what a tester demonstrates is possible once inside, and how professionally that access is documented and removed afterward.

Exam tip. Any mechanism built to survive a reboot or patch cycle is a persistence technique, regardless of its specific implementation.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. After gaining initial access to a server, an attacker installs a mechanism that will automatically re-establish their access even after the server is rebooted or the original vulnerability is patched. What is this concept called?

  • A. Persistencecorrect
  • B. Pivoting
  • C. Enumeration
  • D. Reconnaissance

Persistence refers to techniques that maintain an attacker's access to a compromised system across reboots or after the original entry point is closed. Pivoting refers to using a compromised host to reach other systems, enumeration refers to actively identifying resources on a target, and reconnaissance refers to information gathering, none of which describe maintaining long-term access on an already-compromised host.

Work the whole objective

The full CompTIA PenTest+ bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free CompTIA PenTest+ practice test

The other CompTIA PenTest+ objectives