Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?

⚠ Common exam trap

It's easy for candidates to confuse secretsdump with tools like psexec or wmiexec, which are for remote execution, not credential extraction, or with GetUserSPNs, which targets Kerberos tickets rather than local SAM hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

secretsdump

Secretsdump, because it is the Impacket tool specifically designed to extract password hashes from a Windows SAM database, as well as from NTDS.dit and LSA secrets. It remotely accesses the SAM hive via the Windows registry or uses Volume Shadow Copy to dump hashes without requiring interactive login.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GetUserSPNs

    Why it's wrong here

    GetUserSPNs is an Impacket script that identifies user accounts with Service Principal Names in Active Directory, then requests Kerberos TGS tickets for offline password cracking—a technique known as Kerberoasting. It operates entirely against domain controllers and Active Directory, requiring only valid domain credentials, and never touches the local SAM database or LSASS process memory on the compromised Windows host. Therefore, it cannot extract the local password hashes the question asks about.

  • ✓

    secretsdump

    Why this is correct

    secretsdump is the correct tool because it directly extracts credential material from multiple Windows sources: local SAM and SYSTEM hives via the registry, cached domain credentials from the LSA, NTDS.dit from domain controllers, and LSASS memory on a compromised machine. When run as SYSTEM or with administrator privileges, it can accomplish this remotely using SMB or execute locally, making it the standard Impacket utility for dumping password hashes. This aligns exactly with the post-compromise scenario described.

  • ✗

    psexec

    Why it's wrong here

    psexec (and Impacket's PsExec) executes commands on remote Windows systems by creating a service via SMB admin shares and then waiting for output, making it a lateral movement or remote administration tool. It requires existing credentials or hashes to authenticate, but it does not itself read, parse, or output password hashes from memory or disk. Its typical use in penetration tests is to run other tools once access is obtained, not to perform the extraction step.

  • ✗

    wmiexec

    Why it's wrong here

    wmiexec provides a semi-interactive command shell by creating processes with WMI and reading output over SMB, which is useful for executing commands without touching the disk and with fewer service-control artifacts. Its purpose is remote code execution and command execution, not credential dumping; it never queries the SAM registry hive, LSASS process, or NTDS.dit. Because it does not include hash-extraction routines, choosing wmiexec would fail to meet the objective of obtaining local password hashes.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.