GCIH Attacking Passwords Practice Question
Exhibit
C:\> mimikatz.exe # privilege::debug # sekurlsa::logonpasswords
Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?
⚠ Common exam trap
Candidates often confuse memory dumping with network sniffing. They fail to identify that Mimikatz interacts directly with the LSASS process to extract credentials stored in system memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It retrieves cleartext credentials from LSASS memory
The 'sekurlsa::logonpasswords' command extracts cleartext passwords and NTLM hashes for all users who have recently logged into the system, directly from the LSASS memory process. This is a 'game over' scenario because the attacker gains valid, active credentials, allowing them to impersonate the user across the entire network, often without needing to perform further brute-force or cracking attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It cracks the SAM database file offline
Why it's wrong here
This command operates on memory, not the SAM database file. The SAM database is stored on disk and is only accessible with system privileges. The command specifically targets the LSASS process memory to retrieve credentials currently held by the Windows authentication subsystem.
- ✓
It retrieves cleartext credentials from LSASS memory
Why this is correct
The command dumps the contents of LSASS memory, which often holds cleartext passwords for logged-in users, as well as NTLM hashes and Kerberos tickets. Gaining these credentials allows an attacker to move laterally throughout the domain with the privileges of the victim.
- ✗
It resets the local Administrator password
Why it's wrong here
This command does not modify credentials; it only reads them. Resetting the Administrator password requires different commands (e.g., 'token::elevate' followed by password change utilities). Its primary utility is credential harvesting, not credential modification or administrative password resets.
- ✗
It clears the event logs to hide the attack
Why it's wrong here
Clearing logs is done using commands like 'event::clear'. Extracting credentials from memory is purely a harvesting operation. While attackers may clear logs afterwards, 'sekurlsa::logonpasswords' has no inherent log-clearing functionality; its purpose is solely to steal identity information.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.