Courseiva
Security Operations →easyMultiple Choice

CAS-004 Security Operations Practice Question

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?

⚠ Common exam trap

The trap is that SQL injection and XSS are famous attack names, so candidates pick them without checking whether the question asks about lateral movement versus initial access — the key is recognizing that lateral movement in Windows almost always involves credential abuse like Pass-the-Hash.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-the-Hash

Pass-the-Hash (PtH) is a credential theft technique where an attacker captures NTLM password hashes (e.g., via Mimikatz from LSASS memory) and uses them to authenticate to other Windows systems without cracking the plaintext password. It is one of the most common lateral movement techniques in Windows environments because NTLM authentication accepts the hash directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets the database application layer, granting data access or code execution inside the DBMS, but it does not establish authenticated sessions or run commands on the underlying Windows host. It is tempting because the target is a database server, yet lateral movement requires host-level credentials, such as Pass-the-Hash or RDP.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS executes script in a victim's browser, affecting client sessions rather than pivoting the tester onto another server. It is tempting because it is a common web attack and the entry point was a web server, but lateral movement to a database host needs credential reuse or remote service exploitation, not browser-side scripting.

  • ✓

    Pass-the-Hash

    Why this is correct

    Pass-the-Hash reuses captured NTLM password hashes to authenticate to remote Windows systems without cracking the plaintext password, enabling lateral movement between hosts. This satisfies the scenario's Windows lateral-movement requirement by leveraging credential material already obtained during initial access.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing operates at layer 2 to intercept traffic on a local segment; it does not authenticate to remote Windows hosts or execute commands on the database server. It is tempting because it enables man-in-the-middle positioning, and would be the right choice when sniffing or redirecting traffic within the same broadcast domain.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.