Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, you successfully execute a Meterpreter session on a Windows target. You want to dump password hashes from the SAM database. Which Meterpreter command should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hashdump

hashdump is the Meterpreter command to dump SAM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    getsystem

    Why it's wrong here

    getsystem is a Meterpreter command that attempts to elevate privileges to NT AUTHORITY\SYSTEM by exploiting a token impersonation vulnerability or using named pipe impersonation, typically via the 'getsystem' post-exploitation module. It does not interact with the SAM or LSASS to extract password hashes; it merely changes the security context of the Meterpreter session. While having SYSTEM privileges is often necessary to access the SAM database, the command itself does not retrieve or display any hash material. Therefore, it fails the specific goal of dumping password hashes.

  • ✓

    hashdump

    Why this is correct

    hashdump is a Meterpreter command that reads the Local Security Authority (LSA) secrets and the Security Account Manager (SAM) registry hive from the target system, extracting the NTLM hashes of local user account passwords. It requires SYSTEM privileges to successfully read the SAM database, and it outputs the username, RID, LM hash, and NTLM hash for each account. This is the direct and intended method to dump password hashes from a Windows system, making it the correct answer.

  • ✗

    getuid

    Why it's wrong here

    getuid is a Meterpreter command that prints the user ID (username) and the security context under which the current Meterpreter session is running, such as 'NT AUTHORITY\SYSTEM' or 'DESKTOP\admin'. It provides no access to password hash storage and does not read any part of the SAM or LSASS. Its sole purpose is to confirm the identity of the compromised user, not to extract credentials, so it cannot fulfill the task of dumping hashes.

  • ✗

    sysinfo

    Why it's wrong here

    sysinfo is a Meterpreter command that displays general system information, including computer name, OS version, architecture, and sometimes the system language and domain. It is a reconnaissance/enumeration command used to understand the target environment, but it does not touch the SAM, LSASS, or any credential store. Retrieving password hashes is a completely separate function, and sysinfo's output contains no hash values.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.