200-201 Network Intrusion Analysis Practice Question
An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:
⚠ Common exam trap
200-201 often tests the distinction between pass-the-hash (NTLM hash reuse) and pass-the-ticket (Kerberos ticket reuse), so candidates must match the credential type to the technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-the-hash
Pass-the-hash is the technique where an attacker uses a captured NTLM password hash directly to authenticate without knowing the plaintext password. Because NTLM authentication accepts the hash as the credential, the attacker can replay it to access systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password spraying
Why it's wrong here
Password spraying tries one common password across many accounts to avoid lockouts; it submits plaintext guesses, not a captured hash. It is tempting because both are credential attacks, but spraying does not reuse an intercepted NTLM hash, so it does not match the described technique.
- ✗
Brute force
Why it's wrong here
Brute force repeatedly guesses plaintext passwords against an account; it does not replay a captured hash. It is tempting because both attacks target authentication credentials, but brute force generates guesses rather than reusing an intercepted NTLM hash, which is pass-the-hash.
- ✗
Kerberos ticket reuse
Why it's wrong here
Kerberos ticket reuse replays a stolen TGT or service ticket within a Kerberos realm; NTLM authentication does not involve Kerberos tickets. It is tempting because both are credential-replay techniques, but the stem specifies NTLM with a hashed password, which is pass-the-hash, not ticket reuse.
- ✓
Pass-the-hash
Why this is correct
Pass-the-hash exploits the NTLM challenge-response protocol: the attacker captures the static NT hash and replays it directly, authenticating without ever cracking it to plaintext. This matches the stem's constraint of authentication using a hashed password rather than the cleartext credential.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.