PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing a password attack on a Windows domain and has captured NTLM hashes. Which tool can be used to perform a pass-the-hash attack to gain remote code execution on a target system?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pth-winexe
pth-winexe is a tool specifically designed for pass-the-hash attacks to execute commands on remote Windows systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat
Why it's wrong here
Hashcat is a powerful, GPU-accelerated offline password recovery tool that cracks NTLM, NTLMv2, and many other hash types by comparing candidate plaintexts' computed hashes. It does not have any network protocol implementation to submit a known hash for authentication, so it cannot perform pass-the-hash. In a pass-the-hash scenario, you already have the hash and simply need to present it as a credential via SMB or other services, which is a direct authentication action rather than a cracking attempt.
- ✗
Responder
Why it's wrong here
Responder is a network poisoning tool that passively listens for LLMNR, NBT-NS, and mDNS broadcasts, then spoofs responses to capture NTLMv2 hashes from clients attempting authentication. It does not replay or use those hashes to authenticate to other systems; its job ends at gathering the hash material for a separate offline cracking step. Pass-the-hash tools like pth-winexe take a captured hash and actively forge an authentication request to a target service, which is a fundamentally different post-exploitation action.
- ✓
pth-winexe
Why this is correct
pth-winexe is part of the pass-the-hash toolkit that implements the Windows SMB client and authentication stack, allowing you to authenticate to a remote Windows host using only the NTLM hash as the credential. It substitutes the password in the NTLM/SPNEGO exchange with the hash, establishes an authenticated session, and executes a specified command without ever knowing the plaintext password. This directly demonstrates pass-the-hash: the hash itself serves as the proof of knowledge to impersonate the user.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is an offline password cracker that operates on hash dump files and attempts to recover the original plaintext through modes like wordlists, rules, and brute force. It does not interface with any network authentication protocol, so it cannot submit a captured NTLM hash as a credential to a remote service or share. Unlike pass-the-hash, which immediately allows lateral movement using the hash, John seeks to discover the password itself, a step that is often irrelevant when the hash alone is sufficient.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.