exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 14 discussion

Actual exam question from CompTIA's PT0-002
Question #: 14
Topic #: 1
[All PT0-002 Questions]

Which of the following describes the reason why a penetration tester would run the command sdelete mimikatz. * on a Windows server that the tester compromised?

  • A. To remove hash-cracking registry entries
  • B. To remove the tester-created Mimikatz account
  • C. To remove tools from the server
  • D. To remove a reverse shell from the system
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Manzer
Highly Voted 2 years, 6 months ago
Selected Answer: C
sdelete is used to delete files and folders. This command would delete any folder with mimikatz.*
upvoted 10 times
duckduckgooo
1 year, 4 months ago
I like adding URL's to answers/tools for others or people that had to validate the answer (me). https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete
upvoted 3 times
...
...
petercorn
Highly Voted 2 years, 6 months ago
Selected Answer: C
Agree with Manzer
upvoted 7 times
...
Practice_all
Most Recent 3 months ago
Selected Answer: C
C. To remove tools from the server The command sdelete mimikatz.* uses SDelete (a secure delete tool from Sysinternals) to securely delete files related to Mimikatz, a post-exploitation tool commonly used to extract credentials from memory, dump password hashes, and more. The purpose of running this command is to ensure that traces of the tool are completely removed from the compromised server to cover the tester's tracks.
upvoted 1 times
...
bromings
7 months, 1 week ago
Selected Answer: C
SDelete is a command line utility that takes a number of options. In any given use, it allows you to delete one or more files and/or directories, or to cleanse the free space on a logical disk. SDelete accepts wild card characters as part of the directory or file specifier.
upvoted 4 times
...
Etc_Shadow28000
7 months, 1 week ago
Selected Answer: C
The reason a penetration tester would run the command `sdelete mimikatz.*` on a Windows server that the tester compromised is: C. To remove tools from the server `sdelete` is a command-line utility that securely deletes files, making them unrecoverable. Running `sdelete mimikatz.*` would securely delete the Mimikatz tool and any related files from the server, helping to cover the tester's tracks by removing evidence of the tool's presence and use.
upvoted 1 times
...
solutionz
7 months, 1 week ago
Selected Answer: C
The command `sdelete` is a command-line utility that can be used to securely delete files and cleanse free space on a disk in Windows. `Mimikatz` is a well-known tool used by attackers (and penetration testers) to extract plaintext passwords, hash, PIN code, and Kerberos tickets from memory. In the context of the given command `sdelete mimikatz.*`, the intention is to securely delete all files related to Mimikatz from the compromised server. So the correct answer to this question would be: C. To remove tools from the server.
upvoted 3 times
...
monkeyyyyy
1 year, 4 months ago
Selected Answer: C
vote for C
upvoted 1 times
...
cy_analyst
2 years, 1 month ago
Selected Answer: C
The sdelete command is used to securely delete files or free space on a hard drive by overwriting them with random data. Mimikatz is a tool that can be used to extract sensitive information such as passwords from a compromised Windows system.
upvoted 3 times
...
user009
2 years, 1 month ago
The reason why a penetration tester would run the command sdelete mimikatz.* on a Windows server that the tester compromised is option C: To remove tools from the server. Explanation: Sdelete is a Windows command-line utility that securely deletes files and folders from a disk by overwriting the data with zeroes or random characters. Mimikatz is a post-exploitation tool that can be used to extract passwords and other sensitive information from a compromised Windows system. In this scenario, the penetration tester has compromised the Windows server and has used Mimikatz to extract sensitive information. The command sdelete mimikatz.* is used to securely delete the Mimikatz tool and any related files from the system to avoid leaving traces of the attack.
upvoted 2 times
...
KingIT_ENG
2 years, 1 month ago
CCCCCCCC
upvoted 1 times
...
nickwen007
2 years, 1 month ago
SDelete is a command-line utility used to securely delete files, directories and registry entries. It can also be used to remove traces of Mimikatz, a tool used to manipulate Windows authentication mechanisms. To use SDelete to remove Mimikatz, you must enter the command "sdelete -p 1 mimikatz.*" in elevated command prompt. This will overwrite all files that contain the string "mimikatz" with random data, thus removing any trace of Mimikatz from your computer.
upvoted 2 times
...
nickwen007
2 years, 1 month ago
The most likely reason why a penetration tester would run the command sdelete mimikatz.* on a Windows server is C. To remove tools from the server. This command can be used to securely delete any tools or malicious files that the tester may have installed while compromising the system, such as Mimikatz or any other malicious code.
upvoted 3 times
...
Masco
2 years, 5 months ago
Correct Answer is C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago