PT0-002 Vulnerability Discovery and Analysis Practice Question
After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?
⚠ Common exam trap
It's easy for candidates to confuse secretsdump with tools like psexec or wmiexec, which are for remote execution, not credential extraction, or with GetUserSPNs, which targets Kerberos tickets rather than local SAM hashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
secretsdump
Secretsdump, because it is the Impacket tool specifically designed to extract password hashes from a Windows SAM database, as well as from NTDS.dit and LSA secrets. It remotely accesses the SAM hive via the Windows registry or uses Volume Shadow Copy to dump hashes without requiring interactive login.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GetUserSPNs
Why it's wrong here
GetUserSPNs is an Impacket script that identifies user accounts with Service Principal Names in Active Directory, then requests Kerberos TGS tickets for offline password cracking—a technique known as Kerberoasting. It operates entirely against domain controllers and Active Directory, requiring only valid domain credentials, and never touches the local SAM database or LSASS process memory on the compromised Windows host. Therefore, it cannot extract the local password hashes the question asks about.
- ✓
secretsdump
Why this is correct
secretsdump is the correct tool because it directly extracts credential material from multiple Windows sources: local SAM and SYSTEM hives via the registry, cached domain credentials from the LSA, NTDS.dit from domain controllers, and LSASS memory on a compromised machine. When run as SYSTEM or with administrator privileges, it can accomplish this remotely using SMB or execute locally, making it the standard Impacket utility for dumping password hashes. This aligns exactly with the post-compromise scenario described.
- ✗
psexec
Why it's wrong here
psexec (and Impacket's PsExec) executes commands on remote Windows systems by creating a service via SMB admin shares and then waiting for output, making it a lateral movement or remote administration tool. It requires existing credentials or hashes to authenticate, but it does not itself read, parse, or output password hashes from memory or disk. Its typical use in penetration tests is to run other tools once access is obtained, not to perform the extraction step.
- ✗
wmiexec
Why it's wrong here
wmiexec provides a semi-interactive command shell by creating processes with WMI and reading output over SMB, which is useful for executing commands without touching the disk and with fewer service-control artifacts. Its purpose is remote code execution and command execution, not credential dumping; it never queries the SAM registry hive, LSASS process, or NTDS.dit. Because it does not include hash-extraction routines, choosing wmiexec would fail to meet the objective of obtaining local password hashes.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.