Courseiva
Metasploit →mediumMultiple Choice

GPEN Metasploit Practice Question

A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?

⚠ Common exam trap

The trap here is assuming hashdump or smart_hashdump extracts credentials from LSASS memory, when they primarily target the SAM database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

post/windows/gather/credentials/mimikatz

To extract credentials from LSASS memory, the Mimikatz-based post module is the appropriate choice. It interacts with LSASS to retrieve plaintext passwords, NTLM hashes, and Kerberos tickets. Other modules like hashdump and smart_hashdump target the SAM database or NTDS.dit, and credential_collector gathers from registry and files, so they do not meet the specific requirement of memory credential harvesting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    post/windows/gather/smart_hashdump

    Why it's wrong here

    smart_hashdump is an improved hashdump that can extract hashes from domain controllers and local systems, but it still targets the SAM database and NTDS.dit, not LSASS memory. It is useful for hash extraction but does not specifically harvest credentials from LSASS.

  • ✓

    post/windows/gather/credentials/mimikatz

    Why this is correct

    The mimikatz module in Metasploit uses the Mimikatz tool to extract credentials from LSASS memory, including plaintext passwords, hashes, and Kerberos tickets. It runs in memory without uploading additional tools, directly satisfying the requirement to harvest credentials from memory on the compromised Windows host.

  • ✗

    post/windows/gather/hashdump

    Why it's wrong here

    hashdump is a classic module that extracts local account password hashes from the SAM database, not from LSASS memory. It is useful for obtaining local user hashes, but it does not target LSASS and may not capture domain credentials cached in memory. It does not meet the requirement of harvesting credentials from memory.

  • ✗

    post/windows/gather/credentials/credential_collector

    Why it's wrong here

    credential_collector gathers credentials from various sources such as registry and files, but it does not extract hashes directly from LSASS memory. It may collect saved credentials and configuration data, but it is not the module designed to dump LSASS memory for password hashes.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.