easyMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Bash script…
A penetration tester is analyzing a Bash script used for post-exploitation enumeration. The script contains the line: `cat /etc/shadow | awk -F: '{print $1, $2}'`. What is the primary purpose of this command?
⚠ Common exam trap
Many exam-takers confuse `/etc/shadow` with `/etc/passwd`, which stores user metadata like home directories, leading them to incorrectly select option C instead of recognizing the hash extraction purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Display all usernames and their associated password hashes
The command `cat /etc/shadow | awk -F: '{print $1, $2}'` reads the shadow file, which stores user account information including password hashes. The `-F:` sets the field separator to colon, and `{print $1, $2}` outputs the first field (username) and second field (password hash). This is a common post-exploitation technique to extract password hashes for offline cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Display all usernames and their associated password hashes
Why this is correct
The command parses the /etc/shadow file, which stores user authentication data in colon-delimited fields. The first field is the username and the second is the password hash (or a placeholder like ! or * for locked accounts). By printing these two fields, the script effectively dumps every local user's account name alongside its cryptographic hash, enabling offline password cracking with tools like John the Ripper or Hashcat. This is a classic post-exploitation credential-gathering technique, but it requires root or CAP_DAC_READ_SEARCH privileges to read /etc/shadow.
- ✗
Show the number of users in the system
Why it's wrong here
This option misinterprets the script's output as a numeric count. The command writes one line per user account to standard output, which merely displays the data; it does not aggregate or summarize anything. To produce a user count, the output would need to be piped to `wc -l`, which counts the number of lines and thus the number of shadow entries. Without such a pipe, the script shows the accounts themselves, not a tally, so if the goal were enumeration, the tester would see usernames and hashes, not a total.
- ✗
Extract the usernames and home directories
Why it's wrong here
This is factually impossible: /etc/shadow does not contain home directory information. Home directory paths are defined in the passwd database (/etc/passwd), typically in the sixth colon-separated field. The shadow file's schema is dedicated to password hashes and password aging data, with fields for username, hash, last change, and policy timestamps. Therefore, any command reading /etc/shadow cannot extract a username and home directory pair; that data would come from a different file, so this option misidentifies the source file's purpose.
- ✗
List the account expiration dates
Why it's wrong here
Account expiration dates exist in /etc/shadow, but they reside in the eighth field (and were added later in Linux's shadow history), not in the first two fields that this script outputs. The script explicitly selects field 1 and field 2, which correspond to username and hash, and discards the remaining fields that hold password aging and expiration metadata. Hence, even though the source file contains expiration data, the command's field selection precludes it from printing those values. This option confuses the file's content with the command's specific extraction logic.
Go deeper
Related to this question
Learn chapter
BloodHound and Active Directory Enumeration
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
Key term
Bash script
A Bash script is a text file containing a sequence of commands for the Unix shell Bash, allowing users to automate repetitive tasks and streamline system administration on Linux and macOS.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.