PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester captures NTLM hashes using Responder. Which of the following techniques would allow the tester to authenticate to a remote server without cracking the password?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-the-hash
Pass-the-hash uses captured NTLM hashes to authenticate directly, bypassing the need to crack the password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LLMNR poisoning
Why it's wrong here
LLMNR poisoning responds to LLMNR/NetBIOS name resolution requests to capture NetNTLMv2 challenge-response hashes from victims. The captured hashes are challenge-based and cannot be directly used to authenticate in a pass-the-hash attack; they must be either cracked offline or relayed to a target service, requiring additional conditions. Thus LLMNR poisoning is a hash capture technique, not a direct authentication bypass.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting extracts service tickets (TGS) encrypted with the password hash of a service account, typically for offline brute-force cracking. The resulting material is not an NTLM hash that can be replayed in a pass-the-hash attack; it must be cracked to reveal the plaintext password before any authentication can be attempted. Kerberoasting is therefore an offline password recovery technique, not a direct authentication method.
- ✓
Pass-the-hash
Why this is correct
Pass-the-hash is the correct answer because it directly uses the NTLM hash of a user's password as a credential to authenticate to remote services. In NTLM authentication, the hash itself is the secret, so an attacker who captures or extracts the hash can forge authentication requests without knowing the plaintext password. Tools like Mimikatz inject the hash into memory to obtain access, making this a direct hash-based authentication attack.
- ✗
Rainbow table attack
Why it's wrong here
A rainbow table attack precomputes large chains of plaintext-to-hash mappings to speed up the offline cracking of password hashes. It is purely a cracking method: the attacker looks up a captured hash to reverse it to a plaintext password, but cannot directly authenticate using the hash itself. Because the goal is password recovery rather than hash replay, rainbow tables are not a form of pass-the-hash.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.