PT0-002 Attacks and Exploits Practice Question
A penetration tester has gained access to a Linux server and wants to move laterally to a Windows server. The tester captured a hash of a domain user. Which tool can be used to authenticate to the Windows server using the hash?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
evil-winrm
evil-winrm supports pass-the-hash authentication over WinRM, allowing lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
evil-winrm
Why this is correct
evil-winrm is the correct choice because it natively supports pass-the-hash authentication against the WinRM service. Using the --hash flag, an attacker can authenticate with an NTLM hash (LM:NT) directly, circumventing the need for a cleartext password. This tool also provides an interactive PowerShell shell, making it a standard lateral-movement utility for post-exploitation on Windows servers.
- ✗
Ligolo-ng
Why it's wrong here
Ligolo-ng is a modern tunneling tool designed to create reverse SOCKS5 proxies or full TCP forwarding through an already-compromised host. It does not perform authentication of any kind; it merely relays traffic and establishes encrypted tunnels. Since the attacker already has a session on a Linux server, Ligolo-ng would be used for pivoting to other hosts, not for authenticating to the Windows target.
- ✗
SSH
Why it's wrong here
SSH is an invalid option because its authentication protocol does not accept NTLM hashes; it strictly requires either a password or an SSH private key. While SSH keys can be leveraged for pass-the-key, there is no equivalent to pass-the-hash for NTLM within the SSH standard. Even if the server were Linux, SSH would not assist in authenticating to WinRM, as it operates on Port 22 and uses a completely different credential format.
- ✗
Chisel
Why it's wrong here
Chisel is a fast HTTP/WebSocket-based tunneling utility that encapsulates arbitrary TCP streams through a single encrypted channel. Like Ligolo-ng, it has no authentication primitives and cannot submit credentials or hashes to a remote service. Its purpose is to bypass network restrictions and create advanced forwarding paths, so attempting to use it for hash-based authentication is fundamentally incorrect.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.