nerdexam
CompTIA

PT0-002 · Question #139

Which of the following describes the reason why a penetration tester would run the command on a Windows server that the tester compromised? sdelete mimikatz. *

The correct answer is C. To remove tools from the server. SDelete is a command line utility that takes a number of options. In any given use, it allows you to delete one or more files and/or directories, or to cleanse the free space on a logical disk. SDelete accepts wild card characters as part of the directory or file specifier.

Post-exploitation and lateral movement

Question

Which of the following describes the reason why a penetration tester would run the command on a Windows server that the tester compromised? sdelete mimikatz. *

Options

  • ATo remove hash-cracking registry entries
  • BTo remove the tester-created Mimikatz account
  • CTo remove tools from the server
  • DTo remove a reverse shell from the system

How the community answered

(35 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    80% (28)
  • D
    6% (2)

Explanation

SDelete is a command line utility that takes a number of options. In any given use, it allows you to delete one or more files and/or directories, or to cleanse the free space on a logical disk. SDelete accepts wild card characters as part of the directory or file specifier.

Topics

#Post-exploitation cleanup#Mimikatz#Secure file deletion#Operational security

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice