CAS-004 Security Operations Practice Question
During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?
⚠ Common exam trap
The trap is that SQL injection and XSS are famous attack names, so candidates pick them without checking whether the question asks about lateral movement versus initial access — the key is recognizing that lateral movement in Windows almost always involves credential abuse like Pass-the-Hash.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-the-Hash
Pass-the-Hash (PtH) is a credential theft technique where an attacker captures NTLM password hashes (e.g., via Mimikatz from LSASS memory) and uses them to authenticate to other Windows systems without cracking the plaintext password. It is one of the most common lateral movement techniques in Windows environments because NTLM authentication accepts the hash directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection targets the database application layer, granting data access or code execution inside the DBMS, but it does not establish authenticated sessions or run commands on the underlying Windows host. It is tempting because the target is a database server, yet lateral movement requires host-level credentials, such as Pass-the-Hash or RDP.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
XSS executes script in a victim's browser, affecting client sessions rather than pivoting the tester onto another server. It is tempting because it is a common web attack and the entry point was a web server, but lateral movement to a database host needs credential reuse or remote service exploitation, not browser-side scripting.
- ✓
Pass-the-Hash
Why this is correct
Pass-the-Hash reuses captured NTLM password hashes to authenticate to remote Windows systems without cracking the plaintext password, enabling lateral movement between hosts. This satisfies the scenario's Windows lateral-movement requirement by leveraging credential material already obtained during initial access.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing operates at layer 2 to intercept traffic on a local segment; it does not authenticate to remote Windows hosts or execute commands on the database server. It is tempting because it enables man-in-the-middle positioning, and would be the right choice when sniffing or redirecting traffic within the same broadcast domain.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.