PT0-002 Attacks and Exploits Practice Question
A penetration tester has obtained a meterpreter session on a Windows target. The tester wants to escalate privileges to SYSTEM and then dump password hashes. Which two meterpreter commands should the tester use in sequence? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
getsystem
First, use getsystem to attempt privilege escalation to SYSTEM (via token stealing or other techniques). Then, use hashdump to dump the SAM database hashes. getuid shows current user, sysinfo shows system info.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
getuid
Why it's wrong here
Running getuid only queries the current Windows security context and displays the user or account name that the Meterpreter session is operating as. It is a passive recon command, not an escalation primitive or a credential-dumping routine. Even if it shows an administrator account, it does not itself raise privileges to SYSTEM or expose password material from the SAM hive.
- ✓
getsystem
Why this is correct
The getsystem command invokes Meterpreter's built-in token impersonation and named-pipe duplication attacks to shift the session's security context to NT AUTHORITY\SYSTEM. This is the direct privilege escalation step in a typical post-exploitation sequence, bridging a limited or admin token to full system-level access. It does not return or display hash values; instead, it grants the elevated rights required by later commands such as hashdump.
- ✗
shell
Why it's wrong here
Spawning a shell with this command drops the agent into a standard cmd.exe process, inheriting the same access token as the original Meterpreter session. It is not a privilege escalation technique and does not automatically invoke any hash dumping or token-stealing logic. A shell merely provides an interactive Windows command environment, which may be useful for manual commands but doesn't replace the purpose of getsystem or hashdump.
- ✓
hashdump
Why this is correct
hashdump reads the built-in SAM database and, when applicable, cached domain credentials to extract LM/NTLM password hashes for offline cracking or pass-the-hash attacks. This is the credential harvesting step, and it normally requires SYSTEM privileges to successfully access the protected registry keys and files. While it can produce the ultimate goal of credential acquisition, it cannot elevate a session from a low-privileged user to SYSTEM.
- ✗
sysinfo
Why it's wrong here
sysinfo returns a summary of the target's operating system version, service pack, architecture, and process environment. This information helps tailor subsequent exploits or understand attack surface, but it has no impact on privilege level or direct credential extraction. It is not an escalation tool and gives no insight into password hashes, making it irrelevant to the immediate objective of gaining SYSTEM.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Meterpreter
Meterpreter is an advanced, dynamically extensible payload that provides an interactive command shell and post-exploitation capabilities within a memory-resident environment during a penetration test.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.