CompTIA PenTest+ (PT0-003)Engagement ManagementMedium
A tester uses Metasploit to gain a shell on a compromised host, then dumps credentials, escalates privileges, and pivots to reach internal systems that were not directly exposed to the internet. According to the Penetration Testing Execution Standard (PTES), which phase does this activity belong to?
- AIntelligence Gathering
- BVulnerability Analysis
- CExploitation
- DPost-Exploitation
Show answer & explanationAnswer & explanation
Correct answer: D. Post-Exploitation
PTES defines Post-Exploitation as the phase where testers determine the value of a compromised machine and maintain control, including privilege escalation, credential harvesting, pillaging, and pivoting to other systems. Exploitation ends once initial access is achieved; everything after that, including lateral movement, falls under Post-Exploitation.
Why the other options are wrong
- A. Intelligence Gathering is early reconnaissance, unrelated to post-access activity.
- B. Vulnerability Analysis identifies weaknesses before any exploitation occurs.
- C. Exploitation is the act of gaining initial access, which already occurred before this activity.
PTES Post-Exploitation
The PTES phase after initial access focused on determining a compromised system's value, escalating privileges, harvesting data, and pivoting to additional targets.
- Follows the Exploitation phase
- Includes privilege escalation, pillaging, and lateral movement
- Feeds findings into the final Reporting phase
Memory trick: Pre-Intel-Threat-Vuln-Exploit-Post-Report: 'Please Include The Vulnerable Exploit, Post Report.'