Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?

⚠ Common exam trap

Candidates often confuse tools for remote execution (psexec.py, wmiexec.py) or Kerberoasting (GetUserSPNs.py) with the specific hash-dumping functionality of secretsdump.py, failing to recognize that only secretsdump.py directly extracts SAM and domain account hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

secretsdump.py

D is correct because secretsdump.py is the Impacket tool specifically designed to extract password hashes from the SAM database and domain account hashes (NTDS.dit) on a Windows domain controller. It can perform remote dump operations using techniques like DRSUAPI replication or volume shadow copy, making it the standard choice for credential harvesting in penetration testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    psexec.py

    Why it's wrong here

    PsExec is an Impacket remote administration tool that executes commands on a target system by creating a Windows service via the Service Control Manager (SVCCTL) over SMB. Its purpose is to provide an interactive shell or run arbitrary commands, not to read the SAM, NTDS.dit, or LSA secrets. Therefore, it would not be used to extract password hashes after gaining access to a domain controller.

  • ✗

    GetUserSPNs.py

    Why it's wrong here

    GetUserSPNs.py is an Impacket script designed for Kerberoasting: it queries Active Directory for user accounts with Service Principal Names (SPNs) and requests service tickets (TGS) from the Key Distribution Center. These tickets are formatted for offline password cracking, but they only expose hashes for specific service accounts, not all domain users or computer accounts. Thus, while useful for privilege escalation, it does not dump the full set of hashes that reside in NTDS.dit on a domain controller.

  • ✗

    wmiexec.py

    Why it's wrong here

    wmiexec.py uses Windows Management Instrumentation (WMI) to execute commands remotely, creating a semi-interactive shell via classes like Win32_Process and requiring an administrative account with WMI access. It operates by spawning new processes on the target but never reads the registry hive files or database files where password hashes are stored, so it cannot be used to extract credentials. It is an alternative to PsExec for remote code execution, not a hash-dumping utility.

  • ✓

    secretsdump.py

    Why this is correct

    secretsdump.py is an Impacket tool that copies the SAM, SYSTEM, and SECURITY hives from a local Windows machine, or remotely retrieves NTDS.dit and registry data using Volume Shadow Copy or the DRSUAPI (DCSync) protocol. On a domain controller, it can extract all domain password hashes, including NTDS.dit database and cached credentials, without requiring additional tools on the target. Its ability to perform DCSync and remote registry reads makes it the standard for credential harvesting after gaining admin access to Active Directory.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.