PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
secretsdump.py
Mimikatz is a well-known credential dumping tool, and secretsdump.py from Impacket can dump hashes remotely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
secretsdump.py
Why this is correct
secretsdump.py is an Impacket script that extracts credential material from persistent Windows stores: the local SAM hive, cached domain credentials in the SECURITY hive, and NTDS.dit on domain controllers. It remotely reads registry hives (or receives a local hive dump) and uses the System key to decrypt the Boot Key, then outputs LM/NTLM hashes, Kerberos keys, and plaintext cached credentials. This makes it a powerful post-exploitation tool for lateral movement, but it operates on on-disk files rather than live processes.
- ✓
Mimikatz
Why this is correct
Mimikatz dumps credentials from LSASS (Local Security Authority Subsystem Service) process memory, recovering plaintext passwords, NTLM/SHA1 hashes, Kerberos tickets, and even vault credentials. It requires SeDebugPrivilege or SYSTEM access and typically uses the sekurlsa::logonpasswords module, which parses the memory structures of currently logged-in users. Unlike secretsdump, it does not read SAM/NTDS.dit directly but targets the live memory where authentication secrets are cached; this makes it more effective for capturing interactive Windows logons but also more likely to trigger EDR.
- ✗
Nmap
Why it's wrong here
Nmap is a network discovery and security auditing tool that performs host discovery, port scanning, service/version enumeration, and OS fingerprinting. Although its scripting engine (NSE) includes some credential-related scripts, they only perform network-based tests such as brute-force or banner checks; Nmap does not read local Windows credential stores. In a post-exploitation phase, Nmap might be used for internal reconnaissance, not for dumping the SAM database, NTDS.dit, or LSASS credentials.
- ✗
Hydra
Why it's wrong here
Hydra is an online password-cracking tool that performs dictionary and brute-force attacks against network-authenticated services such as SSH, RDP, HTTP, FTP, and SMB. It is useful during the initial access or horizontal movement phases when trying passwords over a service, but it cannot access a compromised host's local secrets. Because it sends authentication attempts across the network, it is not a post-exploitation credential-dumping technique and is often used to test weak passwords rather than extract stored hashes.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and decodes packets on an interface, allowing inspection of traffic such as unencrypted HTTP, FTP, or SMB. An attacker might sniff cleartext passwords sent over the network, but this only works when credentials are transmitted insecurely and requires the attacker to be on the same network segment. It cannot recover already-stored credentials such as local SAM hashes, cached domain credentials, or LSASS memory contents, so it is not a credential-dumping tool in the post-exploitation sense.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.