Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester captures NTLMv2 hashes using Responder. The tester then uses ntlmrelayx to relay the captured hashes to a target server. Which of the following best describes this attack technique?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTLM relay attack

NTLM relay attacks forward captured authentication attempts to other servers, allowing the attacker to authenticate without cracking the hash. This is distinct from pass-the-hash, which requires a hash of the target account for local authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberoasting attack

    Why it's wrong here

    Kerberoasting targets Kerberos service tickets (TGS) encrypted with the service account's password hash, not NTLM challenge/response hashes. The tester would need valid domain credentials and an SPN to request a ticket, then crack it offline. The captured NTLMv2 hash is an authentication exchange by a client, not a TGS ticket, so Kerberoasting cannot leverage it.

  • ✓

    NTLM relay attack

    Why this is correct

    In an NTLM relay attack, the tester uses tools like Impacket's ntlmrelayx to capture an NTLMv2 challenge/response and immediately forward it to a target service, making the remote server believe the authentication came from the legitimate user. The attacker never needs the password or to crack the hash; the relayed exchange is accepted as valid proof of identity, enabling unauthorized access to services like SMB, HTTP, or LDAP.

  • ✗

    SMB relay attack

    Why it's wrong here

    SMB relay is a specific variant of NTLM relay where the authentication is forwarded to an SMB service. While SMB is a frequent relay target, the generic attack name 'NTLM relay' is more accurate because the same captured NTLMv2 hash can be relayed to LDAP, HTTP, or other protocols. Describing it as only an SMB relay ignores the broader relay capability and the protocol-agnostic nature of the attack.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash requires the actual NT hash (MD4 hash of the password) to authenticate directly, usually via tools like Mimikatz or impacket's psexec. The NTLMv2 hash captured during a challenge/response exchange is the client's response to a server challenge, not the NT hash itself, and cannot be replayed for pass-the-hash. Pass-the-hash does not involve relaying a challenge/response to a separate service; it uses a pre-obtained hash to log in.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.