PT0-002 Attacks and Exploits Practice Question
During a penetration test, you successfully execute a Meterpreter session on a Windows target. You want to dump password hashes from the SAM database. Which Meterpreter command should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
hashdump
hashdump is the Meterpreter command to dump SAM hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
getsystem
Why it's wrong here
getsystem is a Meterpreter command that attempts to elevate privileges to NT AUTHORITY\SYSTEM by exploiting a token impersonation vulnerability or using named pipe impersonation, typically via the 'getsystem' post-exploitation module. It does not interact with the SAM or LSASS to extract password hashes; it merely changes the security context of the Meterpreter session. While having SYSTEM privileges is often necessary to access the SAM database, the command itself does not retrieve or display any hash material. Therefore, it fails the specific goal of dumping password hashes.
- ✓
hashdump
Why this is correct
hashdump is a Meterpreter command that reads the Local Security Authority (LSA) secrets and the Security Account Manager (SAM) registry hive from the target system, extracting the NTLM hashes of local user account passwords. It requires SYSTEM privileges to successfully read the SAM database, and it outputs the username, RID, LM hash, and NTLM hash for each account. This is the direct and intended method to dump password hashes from a Windows system, making it the correct answer.
- ✗
getuid
Why it's wrong here
getuid is a Meterpreter command that prints the user ID (username) and the security context under which the current Meterpreter session is running, such as 'NT AUTHORITY\SYSTEM' or 'DESKTOP\admin'. It provides no access to password hash storage and does not read any part of the SAM or LSASS. Its sole purpose is to confirm the identity of the compromised user, not to extract credentials, so it cannot fulfill the task of dumping hashes.
- ✗
sysinfo
Why it's wrong here
sysinfo is a Meterpreter command that displays general system information, including computer name, OS version, architecture, and sometimes the system language and domain. It is a reconnaissance/enumeration command used to understand the target environment, but it does not touch the SAM, LSASS, or any credential store. Retrieving password hashes is a completely separate function, and sysinfo's output contains no hash values.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.