Skillset can help you prepare! Sign up for your free Skillset account and take the first steps towards your certification.
How can the SAM file or contents of SAM file be collected for offline attacks? Choose all that apply
3. Mounting windows OS into another alternative OS like linux and accessing the SAM file
1. Browsing to %SystemRoot%/system32/config/ and copying the SAM file
4. Using the Locksmith Wizard in the Microsoft Diagnostics and Recovery Toolset (DaRT), part of the Microsoft Desktop Optimization Pack
2. using tools to dump the contents of SAM from memory
You can not simply browse to the SAM folder and copy the file while the OS is running. Windows kernel obtains and keeps an exclusive filesystem lock on the SAM file, and will not release that lock until the operating system has shut down or a "Blue Screen of Death" exception has been thrown. Tools do exist to dump the contents from older versions of Windows. The easiest method to obtain the contents is to boot into another OS and dump the contents into something like 0phCrack. Locksmith is used to reset the password of a local account.
Edit: I doubt "using tools to dump the contents of SAM from memory" is correct in this question because this an offline attack which means SAM is not in the memory, right? ANSWER: By offline attacks, they are referring to attacking the SAM file 'offline' to try to get the passwords from the hashs.
Edit: Since it's an offline attack, dump from memory is not possible, but picking up a copy from the filesystem should be.
Edit: answer "Browsing to %SystemRoot%/system32/config/ and copying the SAM file" is not correct! Using %SystemRoot% suggests that you are trying to copy a file in online mode. Windows (as noticed in explanation above) will not allow that, because file is locked (even for admin with elevated rights). Also answer "using tools to dump the contents of SAM from memory" is true. An example of tools which you can use are DumpIt (to dump memory) and Volatility (to dump SAM content). References: https://www.aldeid.com/wiki/Dumpit, https://www.aldeid.com/wiki/Volatility/Retrieve-password According to this explanation, updating correct answers.
Train with Skillset and pass your certification exam. Faster. Guaranteed.
Study thousands of practice questions that organized by skills and ranked by difficulty.
Create a tailored training plan based on the knowledge you already possess.
Know when you’re ready for the high-stakes exam. Have the confidence that you will pass on your first attempt.