Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any NTLM authentication or administrative logon indicates Pass-the-Hash, when in fact NTLM is still used legitimately; the key is the context of hash reuse without plaintext.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network traffic showing SMB authentication with NTLMSSP messages containing a username and hash.

Pass-the-Hash is an attack where an adversary uses the NTLM hash of a user's password to authenticate without knowing the plaintext. The most direct evidence comes from authentication events that show NTLM usage, such as Windows Security Event ID 4624 with Logon Type 3 and NTLM, and network captures of SMB NTLMSSP authentication. Other events like process creation or privilege assignment are not specific to this technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network traffic showing SMB authentication with NTLMSSP messages containing a username and hash.

    Why this is correct

    Pass-the-Hash attacks often leverage SMB for lateral movement. Capturing network traffic that includes NTLMSSP authentication attempts can reveal the use of NTLM hashes instead of plaintext passwords. Specifically, the NTLMSSP_AUTH message contains the username and the challenge response derived from the hash. If the same hash is used from multiple hosts or in an unusual pattern, it strongly suggests Pass-the-Hash. This artifact provides direct network-level evidence.

  • ✗

    Windows Security Event ID 4688 showing 'svchost.exe' with parent 'services.exe'.

    Why it's wrong here

    Event ID 4688 logs process creation. 'svchost.exe' with parent 'services.exe' is a normal, expected behavior for Windows service hosting. It does not indicate Pass-the-Hash, which is an authentication attack. While process creation logs are valuable for detecting malicious execution, this specific parent-child relationship is benign and not directly related to credential theft or reuse. Therefore, it is not the best evidence.

  • ✓

    Windows Security Event ID 4624 with Logon Type 3 and NTLM authentication.

    Why this is correct

    Event ID 4624 with Logon Type 3 (network logon) and NTLM authentication can indicate a Pass-the-Hash attack because the attacker uses the NTLM hash to authenticate over the network without knowing the plaintext password. This event is generated on the target system when a network logon occurs. While legitimate NTLM network logons exist, in the context of other suspicious activity, this is a strong indicator. It directly shows the use of NTLM for network access.

  • ✗

    Windows Security Event ID 4672 indicating special privileges assigned to a new logon.

    Why it's wrong here

    Event ID 4672 is logged when a logon is granted special privileges, such as SeDebugPrivilege. While this can occur during Pass-the-Hash if the compromised account has administrative rights, it is not specific to the attack. Many legitimate administrative logons also generate this event. It does not directly show the use of a hash for authentication, so it is less direct evidence than the NTLM network logon or SMB traffic.

  • ✗

    Windows Security Event ID 4768 showing a Kerberos TGT request.

    Why it's wrong here

    Event ID 4768 indicates a Kerberos Ticket Granting Ticket (TGT) request. Pass-the-Hash typically involves NTLM authentication, not Kerberos. While Kerberos can be attacked (e.g., Golden Ticket), Pass-the-Hash specifically abuses the NTLM hash. Therefore, a Kerberos TGT request is not direct evidence of Pass-the-Hash. It might be part of normal activity or other attacks, but not this one.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.