Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester captures NTLM hashes using Responder. Which of the following techniques would allow the tester to authenticate to a remote server without cracking the password?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-the-hash

Pass-the-hash uses captured NTLM hashes to authenticate directly, bypassing the need to crack the password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LLMNR poisoning

    Why it's wrong here

    LLMNR poisoning responds to LLMNR/NetBIOS name resolution requests to capture NetNTLMv2 challenge-response hashes from victims. The captured hashes are challenge-based and cannot be directly used to authenticate in a pass-the-hash attack; they must be either cracked offline or relayed to a target service, requiring additional conditions. Thus LLMNR poisoning is a hash capture technique, not a direct authentication bypass.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting extracts service tickets (TGS) encrypted with the password hash of a service account, typically for offline brute-force cracking. The resulting material is not an NTLM hash that can be replayed in a pass-the-hash attack; it must be cracked to reveal the plaintext password before any authentication can be attempted. Kerberoasting is therefore an offline password recovery technique, not a direct authentication method.

  • ✓

    Pass-the-hash

    Why this is correct

    Pass-the-hash is the correct answer because it directly uses the NTLM hash of a user's password as a credential to authenticate to remote services. In NTLM authentication, the hash itself is the secret, so an attacker who captures or extracts the hash can forge authentication requests without knowing the plaintext password. Tools like Mimikatz inject the hash into memory to obtain access, making this a direct hash-based authentication attack.

  • ✗

    Rainbow table attack

    Why it's wrong here

    A rainbow table attack precomputes large chains of plaintext-to-hash mappings to speed up the offline cracking of password hashes. It is purely a cracking method: the attacker looks up a captured hash to reverse it to a plaintext password, but cannot directly authenticate using the hash itself. Because the goal is password recovery rather than hash replay, rainbow tables are not a form of pass-the-hash.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.