easyMultiple Choice
PT0-002 Practice Question: A penetration tester has gained administrative…
A penetration tester has gained administrative access to a Windows system and wants to extract NTLM password hashes from the memory of the Local Security Authority Subsystem Service (LSASS). Which tool is most commonly used for this purpose?
⚠ Common exam trap
Watch out — candidates often confuse hash extraction tools (Mimikatz) with hash cracking tools (John the Ripper, Hashcat), assuming any tool that works with hashes can also extract them from memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mimikatz
Mimikatz is the most commonly used tool for extracting NTLM password hashes from LSASS memory on a Windows system. It leverages the `sekurlsa::logonpasswords` module to read the LSASS process memory and decrypt stored credentials, including NTLM hashes, without requiring a separate brute-force or dictionary attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is a password cracking tool that operates exclusively on pre-extracted hash values, such as those from /etc/shadow or Windows SAM files. It does not have the ability to interact with live system memory or Windows security processes like LSASS. Therefore, even with administrative access on a Windows target, John the Ripper cannot extract credentials from memory; it would require a separate credential-dumping step to provide it with hashes.
- ✓
Mimikatz
Why this is correct
Mimikatz is a specialized post-exploitation tool built for credential extraction from Windows systems, famously accessing LSASS.exe process memory where Windows caches logon credentials to support single sign-on. With administrative privileges, commands like `sekurlsa::logonpasswords` can parse LSASS memory to recover cleartext passwords, NTLM hashes, Kerberos tickets, and PINs. This direct memory-extraction capability makes Mimikatz the correct tool for the scenario described.
- ✗
Hashcat
Why it's wrong here
Hashcat is a high-performance password recovery tool that leverages GPU acceleration to crack hash values via brute-force, dictionary, or rule-based attacks. It is purely an offline computation engine—it cannot read from, query, or dump live process memory on a running system. To use Hashcat, an attacker must first obtain hashes through a separate extraction method, so it is not a credential dumper but rather a final-stage cracking utility.
- ✗
Netcat
Why it's wrong here
Netcat is a network utility that reads and writes raw data over TCP/UDP connections, commonly used for port scanning, banner grabbing, and establishing reverse shells. It has no built-in functionality to access Windows process memory, parse security structures, or interact with LSASS. While Netcat could be used to exfiltrate a credential dump file once created, it cannot perform the extraction itself, making it unsuitable for directly retrieving credentials from memory.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.