Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a Bash script…

A penetration tester is analyzing a Bash script used for post-exploitation enumeration. The script contains the line: `cat /etc/shadow | awk -F: '{print $1, $2}'`. What is the primary purpose of this command?

⚠ Common exam trap

Many exam-takers confuse `/etc/shadow` with `/etc/passwd`, which stores user metadata like home directories, leading them to incorrectly select option C instead of recognizing the hash extraction purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Display all usernames and their associated password hashes

The command `cat /etc/shadow | awk -F: '{print $1, $2}'` reads the shadow file, which stores user account information including password hashes. The `-F:` sets the field separator to colon, and `{print $1, $2}` outputs the first field (username) and second field (password hash). This is a common post-exploitation technique to extract password hashes for offline cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Display all usernames and their associated password hashes

    Why this is correct

    The command parses the /etc/shadow file, which stores user authentication data in colon-delimited fields. The first field is the username and the second is the password hash (or a placeholder like ! or * for locked accounts). By printing these two fields, the script effectively dumps every local user's account name alongside its cryptographic hash, enabling offline password cracking with tools like John the Ripper or Hashcat. This is a classic post-exploitation credential-gathering technique, but it requires root or CAP_DAC_READ_SEARCH privileges to read /etc/shadow.

  • ✗

    Show the number of users in the system

    Why it's wrong here

    This option misinterprets the script's output as a numeric count. The command writes one line per user account to standard output, which merely displays the data; it does not aggregate or summarize anything. To produce a user count, the output would need to be piped to `wc -l`, which counts the number of lines and thus the number of shadow entries. Without such a pipe, the script shows the accounts themselves, not a tally, so if the goal were enumeration, the tester would see usernames and hashes, not a total.

  • ✗

    Extract the usernames and home directories

    Why it's wrong here

    This is factually impossible: /etc/shadow does not contain home directory information. Home directory paths are defined in the passwd database (/etc/passwd), typically in the sixth colon-separated field. The shadow file's schema is dedicated to password hashes and password aging data, with fields for username, hash, last change, and policy timestamps. Therefore, any command reading /etc/shadow cannot extract a username and home directory pair; that data would come from a different file, so this option misidentifies the source file's purpose.

  • ✗

    List the account expiration dates

    Why it's wrong here

    Account expiration dates exist in /etc/shadow, but they reside in the eighth field (and were added later in Linux's shadow history), not in the first two fields that this script outputs. The script explicitly selects field 1 and field 2, which correspond to username and hash, and discards the remaining fields that hold password aging and expiration metadata. Hence, even though the source file contains expiration data, the command's field selection precludes it from printing those values. This option confuses the file's content with the command's specific extraction logic.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.