PT0-002 Attacks and Exploits Practice Question
After compromising a Windows workstation, the tester wants to extract password hashes from the local SAM database. Which Metasploit meterpreter command should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
hashdump
hashdump dumps the SAM database hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
getsystem
Why it's wrong here
Meterpreter's getsystem command attempts to escalate privileges to NT AUTHORITY\SYSTEM using techniques such as named pipe impersonation or token duplication. It does not interact with the Security Account Manager (SAM) registry hive or extract any credential material. Even after successfully calling getsystem, the tester still must run a separate command like hashdump to actually dump password hashes. Therefore, while useful for preconditioning, getsystem does not fulfill the requirement to dump hashes.
- ✗
getuid
Why it's wrong here
The getuid command prints the username and SID associated with the current Meterpreter process, effectively telling the tester which account they are running as. It is a basic identity check that reads process token information, not a post-exploitation or extraction action. Because it never touches the Windows registry (SAM/SYSTEM hives) or LSASS, it produces no credential output whatsoever. For the objective of obtaining password hashes, getuid only verifies the context before performing a proper dump.
- ✗
shell
Why it's wrong here
The shell command drops the tester into a standard interactive command shell (e.g., cmd.exe or /bin/sh), allowing them to run arbitrary OS commands on the compromised host. However, a shell alone does not dump hashes; to extract SAM hashes manually you would need to run multiple utility commands such as 'reg save hklm\sam sam' and 'reg save hklm\system system' before parsing the files offline. Meterpreter's hashdump does that work in a single call by using built-in functionality, whereas shell merely gives you a manual environment. Thus, invoking shell is not a direct means of dumping hashes.
- ✓
hashdump
Why this is correct
The hashdump command is the correct choice because it directly extracts the NTLM password hashes from the SAM database on a Windows target when run in Meterpreter (typically after gaining SYSTEM privileges). It does this by copying the SAM and SYSTEM registry hives, decrypting the hash material with the SYSKEY from the SYSTEM hive, and presenting the hashes in a format ready for offline cracking. This command is specifically designed for dumping local user password hashes, fulfilling the tester's objective immediately. While it may require 'getsystem' first, hashdump itself is the actual dumping action.
Go deeper
Related to this question
Learn chapter
Debriefing the Client After a PenTest
Key term
Meterpreter
Meterpreter is an advanced, dynamically extensible payload that provides an interactive command shell and post-exploitation capabilities within a memory-resident environment during a penetration test.
Key term
Metasploit
Metasploit is a powerful penetration testing framework that helps security professionals find and exploit vulnerabilities in computer systems.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.