PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing an NTLM relay attack against a Windows network. The tester uses ntlmrelayx to relay captured NTLM authentication attempts to a target server. What must be true for this attack to succeed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMB signing must be disabled or not enforced
SMB signing must be disabled or not enforced on the target server, otherwise the relayed authentication will be rejected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LLMNR must be enabled
Why it's wrong here
LLMNR is a name resolution protocol that pentesters often poison to intercept NTLM authentication attempts, but enabling it is not a prerequisite for an NTLM relay attack. Relay attacks can be executed with other name resolution poisoning or via direct network access, and LLMNR's presence or absence does not affect whether a target SMB service accepts relayed credentials. The key requirement is the absence or non-enforcement of SMB signing, not LLMNR.
- ✗
The relayed hash must be crackable
Why it's wrong here
Relay attacks pass the captured NTLM hash (the NT hash or derived response) directly to the target server as proof of identity, so the hash never needs to be cracked or reversed. The server validates the challenge-response exchange using the hash as a secret, and the attacker simply forwards that response to establish a session. Crackability is irrelevant because the attack leverages the hash in its original form, not a recovered plaintext password.
- ✗
The target server must have SMB signing enabled
Why it's wrong here
The statement is incorrect because SMB signing, when enabled and enforced, actually blocks NTLM relay attacks by adding a digital signature to every SMB message that covers the session key, which includes client and server challenges. A relayed authentication from a different session will fail signature verification, so the target server must have SMB signing disabled or merely not enforced for relay to succeed. Requiring signing is the mitigation, not a condition for the attack.
- ✓
SMB signing must be disabled or not enforced
Why this is correct
For an NTLM relay attack against SMB to work, the target server must not require SMB signing, meaning signing is disabled or set to 'Not Enforced.' Without mandatory signing, the server accepts SMB packets without verifying their integrity, allowing an attacker to forward a captured NTLM authentication exchange to establish a session. This is why the correct condition is that SMB signing must be disabled or not enforced, as enforced signing blocks the relay entirely.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.