Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester has gained access to a Linux server and wants to move laterally to a Windows server. The tester captured a hash of a domain user. Which tool can be used to authenticate to the Windows server using the hash?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

evil-winrm

evil-winrm supports pass-the-hash authentication over WinRM, allowing lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    evil-winrm

    Why this is correct

    evil-winrm is the correct choice because it natively supports pass-the-hash authentication against the WinRM service. Using the --hash flag, an attacker can authenticate with an NTLM hash (LM:NT) directly, circumventing the need for a cleartext password. This tool also provides an interactive PowerShell shell, making it a standard lateral-movement utility for post-exploitation on Windows servers.

  • ✗

    Ligolo-ng

    Why it's wrong here

    Ligolo-ng is a modern tunneling tool designed to create reverse SOCKS5 proxies or full TCP forwarding through an already-compromised host. It does not perform authentication of any kind; it merely relays traffic and establishes encrypted tunnels. Since the attacker already has a session on a Linux server, Ligolo-ng would be used for pivoting to other hosts, not for authenticating to the Windows target.

  • ✗

    SSH

    Why it's wrong here

    SSH is an invalid option because its authentication protocol does not accept NTLM hashes; it strictly requires either a password or an SSH private key. While SSH keys can be leveraged for pass-the-key, there is no equivalent to pass-the-hash for NTLM within the SSH standard. Even if the server were Linux, SSH would not assist in authenticating to WinRM, as it operates on Port 22 and uses a completely different credential format.

  • ✗

    Chisel

    Why it's wrong here

    Chisel is a fast HTTP/WebSocket-based tunneling utility that encapsulates arbitrary TCP streams through a single encrypted channel. Like Ligolo-ng, it has no authentication primitives and cannot submit credentials or hashes to a remote service. Its purpose is to bypass network restrictions and create advanced forwarding paths, so attempting to use it for hash-based authentication is fundamentally incorrect.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.