Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester uses Metasploit to exploit a Windows service and gets a meterpreter session. The tester wants to dump hashes from the compromised system. Which meterpreter command should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hashdump

The hashdump command in meterpreter dumps the SAM database hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    hashdump

    Why this is correct

    hashdump is a Metasploit post-exploitation command that directly extracts LM/NTLM password hashes from the Windows Security Account Manager (SAM) database. It typically requires SYSTEM-level privileges, often obtained after successful privilege escalation. The extracted hashes can be saved to a file for offline cracking or used directly in pass-the-hash attacks. This is the specific, built-in command designed for credential harvesting from a compromised Windows host.

  • ✗

    shell

    Why it's wrong here

    shell is a Metasploit command that opens an interactive system shell (e.g., cmd.exe on Windows or /bin/sh on Linux) on the target. While a shell provides a flexible environment where you could manually run tools like reg.exe or pwdump to extract hashes, it is not a direct hash-dumping command itself. The question specifically asks which command is used to dump password hashes, making shell an indirect, generic interface rather than the correct answer.

  • ✗

    sysinfo

    Why it's wrong here

    sysinfo is a Metasploit command that displays basic information about the compromised target, such as the operating system version, architecture, and hostname. It is primarily a reconnaissance tool that helps an attacker tailor subsequent post-exploitation steps. It does not interact with the SAM database or retrieve any credential material, so it is irrelevant to dumping password hashes and therefore incorrect for this question.

  • ✗

    getsystem

    Why it's wrong here

    getsystem is a Metasploit command that attempts to elevate privileges to SYSTEM level on a Windows target, often using token duplication or named pipe impersonation techniques. While gaining SYSTEM privileges is a necessary step for successfully running hashdump, getsystem itself only performs the privilege escalation and does not extract any hashes. It is a supporting action, not the actual command for dumping password hashes from the SAM, which is why it is incorrect.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.