exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 70 discussion

Actual exam question from CompTIA's PT1-002
Question #: 70
Topic #: 1
[All PT1-002 Questions]

A penetration tester runs the unshadow command on a machine. Which of the following tools will the tester most likely use NEXT?

  • A. John the Ripper
  • B. Hydra
  • C. Mimikatz
  • D. Cain and Abel
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Reference:
https://www.cyberciti.biz/faq/unix-linux-password-cracking-john-the-ripper/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
strawberryspring
Highly Voted 3 years, 1 month ago
A. Jtr is a tool for you to crack your hashes. The unshadow command will combine /etc/shadow (where your hashes are stored) and /etc/passwd (list of users found) into one output than you can feed into jtr.
upvoted 6 times
...
bieecop
Most Recent 1 year, 9 months ago
Selected Answer: A
The "unshadow" command is typically used to combine the /etc/passwd and /etc/shadow files on Unix-like systems, creating a single file with hashed passwords that can be used for offline password cracking. By running this command, the tester retrieves the hashed password data, which can then be subjected to password cracking techniques. John the Ripper and Hashcat are both popular password-cracking tools commonly used by penetration testers. These tools utilize various methods, including dictionary-based attacks, brute force attacks, and rainbow table attacks, to attempt to crack the hashed passwords and reveal the plaintext passwords.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago