Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

Which Metasploit command is used to display information about the current meterpreter session, including the target OS and user?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sysinfo

The 'sysinfo' meterpreter command displays system information such as OS, architecture, and sometimes user context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    hashdump

    Why it's wrong here

    hashdump is not used for displaying general system information; instead, it extracts Windows password hashes from the Security Account Manager (SAM) database (or from LSASS memory). This Meterpreter command is a post-exploitation credential harvesting tool, requiring elevated (often SYSTEM) privileges to dump hashes for offline cracking or pass-the-hash attacks.

  • ✗

    getuid

    Why it's wrong here

    getuid serves a very narrow purpose: it returns the username and/or security identifier (SID) of the current Meterpreter process to confirm the identity under which the session is running. Unlike sysinfo, it does not reveal OS version, architecture, or other host-level details, making it useful only for privilege verification, not system reconnaissance.

  • ✗

    getsystem

    Why it's wrong here

    getsystem attempts to win privilege escalation to the Windows SYSTEM account by abusing mechanisms such as named pipe impersonation or token duplication, commonly via the built-in 'getsystem' command in Meterpreter. It changes the access token of the session rather than displaying any system information, and success is typically verified afterward with getuid.

  • ✓

    sysinfo

    Why this is correct

    sysinfo is the correct Meterpreter command for system reconnaissance, as it displays the target operating system version, computer name, architecture (e.g., x64 or x86), and sometimes the Meterpreter payload type and domain. This information lets a penetration tester choose compatible exploits, payloads, or enumeration modules, and it is the first logical step after gaining a session.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.