CompTIA
PT0-002 · Question #139
Which of the following describes the reason why a penetration tester would run the command on a Windows server that the tester compromised? sdelete mimikatz. *
The correct answer is C. To remove tools from the server. SDelete is a command line utility that takes a number of options. In any given use, it allows you to delete one or more files and/or directories, or to cleanse the free space on a logical disk. SDelete accepts wild card characters as part of the directory or file specifier.
Post-exploitation and lateral movement
Question
Which of the following describes the reason why a penetration tester would run the command on a Windows server that the tester compromised? sdelete mimikatz. *
Options
- ATo remove hash-cracking registry entries
- BTo remove the tester-created Mimikatz account
- CTo remove tools from the server
- DTo remove a reverse shell from the system
How the community answered
(35 responses)- A11% (4)
- B3% (1)
- C80% (28)
- D6% (2)
Explanation
SDelete is a command line utility that takes a number of options. In any given use, it allows you to delete one or more files and/or directories, or to cleanse the free space on a logical disk. SDelete accepts wild card characters as part of the directory or file specifier.
Topics
#Post-exploitation cleanup#Mimikatz#Secure file deletion#Operational security
Community Discussion
No community discussion yet for this question.