Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester has gained administrative…

A penetration tester has gained administrative access to a Windows system and wants to extract NTLM password hashes from the memory of the Local Security Authority Subsystem Service (LSASS). Which tool is most commonly used for this purpose?

⚠ Common exam trap

Watch out — candidates often confuse hash extraction tools (Mimikatz) with hash cracking tools (John the Ripper, Hashcat), assuming any tool that works with hashes can also extract them from memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mimikatz

Mimikatz is the most commonly used tool for extracting NTLM password hashes from LSASS memory on a Windows system. It leverages the `sekurlsa::logonpasswords` module to read the LSASS process memory and decrypt stored credentials, including NTLM hashes, without requiring a separate brute-force or dictionary attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    John the Ripper

    Why it's wrong here

    John the Ripper is a password cracking tool that operates exclusively on pre-extracted hash values, such as those from /etc/shadow or Windows SAM files. It does not have the ability to interact with live system memory or Windows security processes like LSASS. Therefore, even with administrative access on a Windows target, John the Ripper cannot extract credentials from memory; it would require a separate credential-dumping step to provide it with hashes.

  • ✓

    Mimikatz

    Why this is correct

    Mimikatz is a specialized post-exploitation tool built for credential extraction from Windows systems, famously accessing LSASS.exe process memory where Windows caches logon credentials to support single sign-on. With administrative privileges, commands like `sekurlsa::logonpasswords` can parse LSASS memory to recover cleartext passwords, NTLM hashes, Kerberos tickets, and PINs. This direct memory-extraction capability makes Mimikatz the correct tool for the scenario described.

  • ✗

    Hashcat

    Why it's wrong here

    Hashcat is a high-performance password recovery tool that leverages GPU acceleration to crack hash values via brute-force, dictionary, or rule-based attacks. It is purely an offline computation engine—it cannot read from, query, or dump live process memory on a running system. To use Hashcat, an attacker must first obtain hashes through a separate extraction method, so it is not a credential dumper but rather a final-stage cracking utility.

  • ✗

    Netcat

    Why it's wrong here

    Netcat is a network utility that reads and writes raw data over TCP/UDP connections, commonly used for port scanning, banner grabbing, and establishing reverse shells. It has no built-in functionality to access Windows process memory, parse security structures, or interact with LSASS. While Netcat could be used to exfiltrate a credential dump file once created, it cannot perform the extraction itself, making it unsuitable for directly retrieving credentials from memory.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.