Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester has obtained a meterpreter session on a Windows target. The tester wants to escalate privileges to SYSTEM and then dump password hashes. Which two meterpreter commands should the tester use in sequence? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

getsystem

First, use getsystem to attempt privilege escalation to SYSTEM (via token stealing or other techniques). Then, use hashdump to dump the SAM database hashes. getuid shows current user, sysinfo shows system info.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    getuid

    Why it's wrong here

    Running getuid only queries the current Windows security context and displays the user or account name that the Meterpreter session is operating as. It is a passive recon command, not an escalation primitive or a credential-dumping routine. Even if it shows an administrator account, it does not itself raise privileges to SYSTEM or expose password material from the SAM hive.

  • ✓

    getsystem

    Why this is correct

    The getsystem command invokes Meterpreter's built-in token impersonation and named-pipe duplication attacks to shift the session's security context to NT AUTHORITY\SYSTEM. This is the direct privilege escalation step in a typical post-exploitation sequence, bridging a limited or admin token to full system-level access. It does not return or display hash values; instead, it grants the elevated rights required by later commands such as hashdump.

  • ✗

    shell

    Why it's wrong here

    Spawning a shell with this command drops the agent into a standard cmd.exe process, inheriting the same access token as the original Meterpreter session. It is not a privilege escalation technique and does not automatically invoke any hash dumping or token-stealing logic. A shell merely provides an interactive Windows command environment, which may be useful for manual commands but doesn't replace the purpose of getsystem or hashdump.

  • ✓

    hashdump

    Why this is correct

    hashdump reads the built-in SAM database and, when applicable, cached domain credentials to extract LM/NTLM password hashes for offline cracking or pass-the-hash attacks. This is the credential harvesting step, and it normally requires SYSTEM privileges to successfully access the protected registry keys and files. While it can produce the ultimate goal of credential acquisition, it cannot elevate a session from a low-privileged user to SYSTEM.

  • ✗

    sysinfo

    Why it's wrong here

    sysinfo returns a summary of the target's operating system version, service pack, architecture, and process environment. This information helps tailor subsequent exploits or understand attack surface, but it has no impact on privilege level or direct credential extraction. It is not an escalation tool and gives no insight into password hashes, making it irrelevant to the immediate objective of gaining SYSTEM.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.