PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester uses Metasploit to exploit a Windows service and gets a meterpreter session. The tester wants to dump hashes from the compromised system. Which meterpreter command should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
hashdump
The hashdump command in meterpreter dumps the SAM database hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
hashdump
Why this is correct
hashdump is a Metasploit post-exploitation command that directly extracts LM/NTLM password hashes from the Windows Security Account Manager (SAM) database. It typically requires SYSTEM-level privileges, often obtained after successful privilege escalation. The extracted hashes can be saved to a file for offline cracking or used directly in pass-the-hash attacks. This is the specific, built-in command designed for credential harvesting from a compromised Windows host.
- ✗
shell
Why it's wrong here
shell is a Metasploit command that opens an interactive system shell (e.g., cmd.exe on Windows or /bin/sh on Linux) on the target. While a shell provides a flexible environment where you could manually run tools like reg.exe or pwdump to extract hashes, it is not a direct hash-dumping command itself. The question specifically asks which command is used to dump password hashes, making shell an indirect, generic interface rather than the correct answer.
- ✗
sysinfo
Why it's wrong here
sysinfo is a Metasploit command that displays basic information about the compromised target, such as the operating system version, architecture, and hostname. It is primarily a reconnaissance tool that helps an attacker tailor subsequent post-exploitation steps. It does not interact with the SAM database or retrieve any credential material, so it is irrelevant to dumping password hashes and therefore incorrect for this question.
- ✗
getsystem
Why it's wrong here
getsystem is a Metasploit command that attempts to elevate privileges to SYSTEM level on a Windows target, often using token duplication or named pipe impersonation techniques. While gaining SYSTEM privileges is a necessary step for successfully running hashdump, getsystem itself only performs the privilege escalation and does not extract any hashes. It is a supporting action, not the actual command for dumping password hashes from the SAM, which is why it is incorrect.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Meterpreter
Meterpreter is an advanced, dynamically extensible payload that provides an interactive command shell and post-exploitation capabilities within a memory-resident environment during a penetration test.
Key term
Metasploit
Metasploit is a powerful penetration testing framework that helps security professionals find and exploit vulnerabilities in computer systems.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.