Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:

⚠ Common exam trap

200-201 often tests the distinction between pass-the-hash (NTLM hash reuse) and pass-the-ticket (Kerberos ticket reuse), so candidates must match the credential type to the technique.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-the-hash

Pass-the-hash is the technique where an attacker uses a captured NTLM password hash directly to authenticate without knowing the plaintext password. Because NTLM authentication accepts the hash as the credential, the attacker can replay it to access systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password spraying

    Why it's wrong here

    Password spraying tries one common password across many accounts to avoid lockouts; it submits plaintext guesses, not a captured hash. It is tempting because both are credential attacks, but spraying does not reuse an intercepted NTLM hash, so it does not match the described technique.

  • ✗

    Brute force

    Why it's wrong here

    Brute force repeatedly guesses plaintext passwords against an account; it does not replay a captured hash. It is tempting because both attacks target authentication credentials, but brute force generates guesses rather than reusing an intercepted NTLM hash, which is pass-the-hash.

  • ✗

    Kerberos ticket reuse

    Why it's wrong here

    Kerberos ticket reuse replays a stolen TGT or service ticket within a Kerberos realm; NTLM authentication does not involve Kerberos tickets. It is tempting because both are credential-replay techniques, but the stem specifies NTLM with a hashed password, which is pass-the-hash, not ticket reuse.

  • ✓

    Pass-the-hash

    Why this is correct

    Pass-the-hash exploits the NTLM challenge-response protocol: the attacker captures the static NT hash and replays it directly, authenticating without ever cracking it to plaintext. This matches the stem's constraint of authentication using a hashed password rather than the cleartext credential.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.