Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

Exhibit

C:\> mimikatz.exe
# privilege::debug
# sekurlsa::logonpasswords

Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?

⚠ Common exam trap

Candidates often confuse memory dumping with network sniffing. They fail to identify that Mimikatz interacts directly with the LSASS process to extract credentials stored in system memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It retrieves cleartext credentials from LSASS memory

The 'sekurlsa::logonpasswords' command extracts cleartext passwords and NTLM hashes for all users who have recently logged into the system, directly from the LSASS memory process. This is a 'game over' scenario because the attacker gains valid, active credentials, allowing them to impersonate the user across the entire network, often without needing to perform further brute-force or cracking attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It cracks the SAM database file offline

    Why it's wrong here

    This command operates on memory, not the SAM database file. The SAM database is stored on disk and is only accessible with system privileges. The command specifically targets the LSASS process memory to retrieve credentials currently held by the Windows authentication subsystem.

  • ✓

    It retrieves cleartext credentials from LSASS memory

    Why this is correct

    The command dumps the contents of LSASS memory, which often holds cleartext passwords for logged-in users, as well as NTLM hashes and Kerberos tickets. Gaining these credentials allows an attacker to move laterally throughout the domain with the privileges of the victim.

  • ✗

    It resets the local Administrator password

    Why it's wrong here

    This command does not modify credentials; it only reads them. Resetting the Administrator password requires different commands (e.g., 'token::elevate' followed by password change utilities). Its primary utility is credential harvesting, not credential modification or administrative password resets.

  • ✗

    It clears the event logs to hide the attack

    Why it's wrong here

    Clearing logs is done using commands like 'event::clear'. Extracting credentials from memory is purely a harvesting operation. While attackers may clear logs afterwards, 'sekurlsa::logonpasswords' has no inherent log-clearing functionality; its purpose is solely to steal identity information.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.