Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?

⚠ Common exam trap

The trap is that candidates pick generic 'suspicious' traffic like large file transfers or Kerberos requests, missing that pass-the-hash has a very specific signature: NTLM authentication with hash material and SMB fan-out from one host to many.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple SMB authentication attempts from a single host to multiple other hosts

Option A is correct because pass-the-hash lateral movement typically manifests as a single compromised host authenticating over SMB (TCP 445) to numerous other hosts in rapid succession, as the attacker reuses the stolen hash to pivot across the network. Option E is correct because the defining characteristic of pass-the-hash is that NTLM authentication succeeds using only the captured NTLM hash (via tools like Mimikatz or Impacket's psexec/smbexec) without ever knowing or supplying the plaintext password. Option B is not a pass-the-hash indicator, since HTTP requests to a web server reflect normal web traffic rather than NTLM-based host-to-host authentication. Option C is unrelated, as ICMP timestamp requests are diagnostic network probes and not part of the NTLM/SMB authentication process. Option D is also unrelated, because FTP file transfers use a separate cleartext protocol and do not demonstrate hash-based credential reuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Multiple SMB authentication attempts from a single host to multiple other hosts

    Why this is correct

    Pass-the-hash lateral movement produces a fan-out pattern: one compromised host authenticating via SMB to many targets in quick succession. This satisfies the stem's requirement for a typical indicator, since legitimate users rarely generate such broad single-source SMB authentication bursts.

  • ✗

    HTTP requests to a web server

    Why it's wrong here

    HTTP requests to a web server describe ordinary application traffic, not the SMB or NTLM authentication artefacts pass-the-hash produces. It is tempting because web requests are easy to spot in a PCAP, but that visibility suits detecting web exploitation, not credential-reuse lateral movement.

  • ✗

    ICMP timestamp requests

    Why it's wrong here

    ICMP timestamp requests are diagnostic probes used in host discovery and network mapping, not authentication. Pass-the-hash appears as NTLM authentication attempts over SMB, WMI or RPC. ICMP timestamp traffic would be relevant when fingerprinting live hosts during reconnaissance, but it carries no credential material.

  • ✗

    Large file transfers using FTP

    Why it's wrong here

    Pass-the-hash reuses captured NTLM hashes to authenticate over SMB or WMI, producing authentication traffic rather than bulk data movement. FTP transfers indicate exfiltration or staging, not credential reuse. Analysts would flag FTP volume when hunting data theft, but it reveals nothing about stolen hash authentication.

  • ✓

    Use of NTLM authentication without a password, only the hash

    Why this is correct

    Pass-the-hash reuses a captured NTLM hash to authenticate, so the PCAP shows NTLM challenge-response exchanges with no preceding password-based logon. This satisfies the stem's requirement for a typical pass-the-hash indicator, distinguishing it from Kerberos-based lateral movement.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.