mediumMultiple Choice
PT0-002 Practice Question: A penetration tester has obtained the NTLM hash…
A penetration tester has obtained the NTLM hash of a local administrator account on a Windows domain-joined system. The tester wants to use this hash to authenticate to another system on the network and execute commands remotely. Which tool is commonly used for pass-the-hash attacks to achieve remote code execution?
⚠ Common exam trap
CompTIA often tests the distinction between tools that require plaintext credentials versus those that can operate directly with NTLM hashes, leading candidates to mistakenly choose PsExec because it is a well-known remote execution tool, even though it does not natively support pass-the-hash without additional credential injection steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Impacket's wmiexec.py
Impacket's wmiexec.py is the correct tool because it directly supports pass-the-hash (PtH) authentication using NTLM hashes over Windows Management Instrumentation (WMI). It accepts an NTLM hash via the `-hashes` flag and establishes a remote WMI session, enabling command execution without needing the plaintext password. This makes it ideal for lateral movement in a domain environment where a local administrator hash has been captured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hydra
Why it's wrong here
Hydra is a parallelized network login cracker designed for online brute-force attacks against services like SSH, RDP, HTTP, or SMB by continuously guessing username/password combinations. It has no capability to impersonate an already-captured NTLM hash; the tool merely submits dictionary-generated credentials across the network. In a pass-the-hash attack, the hash itself is a valid credential, and Hydra's brute-force approach would be both ineffective and highly suspicious, generating excessive network traffic and account lockouts.
- ✓
Impacket's wmiexec.py
Why this is correct
Impacket's wmiexec.py is the correct choice because it directly supports pass-the-hash via the -hashes option, accepting the LM:NTLM hash and using it to authenticate to the target's Windows Management Instrumentation (WMI) service. WMI remoting operates over DCOM/Windows Remote Management, and wmiexec.py leverages the WMI protocol to create remote processes and return their output via a semi-interactive shell. This allows command execution using only the NTLM hash, without needing a plaintext password or any token injection step.
- ✗
PsExec
Why it's wrong here
While PsExec can execute remote processes, the standard Sysinternals PsExec expects a plaintext password or an existing security token and does not natively accept an NTLM hash as a credential argument. To use PsExec in a pass-the-hash scenario, an attacker must first inject the hash into memory to create a security token (e.g., with mimikatz sekurlsa::pth), then run PsExec with that token. This extra dependency on admin shares and token manipulation makes it a less direct and more complex choice than wmiexec.py.
- ✗
Sqlmap
Why it's wrong here
Sqlmap is a database infiltration tool that automates the detection and exploitation of SQL injection vulnerabilities in web applications. It constructs and sends malicious SQL payloads over HTTP(S) to manipulate query logic, not to reuse captured authentication material. Since pass-the-hash requires presenting an NTLM hash as a credential during an authentication handshake (e.g., SMB or WMI), Sqlmap has no mechanism for this purpose and thus would be useless for lateral movement with a hash.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.