PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester captures NTLMv2 hashes using Responder. The tester then uses ntlmrelayx to relay the captured hashes to a target server. Which of the following best describes this attack technique?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTLM relay attack
NTLM relay attacks forward captured authentication attempts to other servers, allowing the attacker to authenticate without cracking the hash. This is distinct from pass-the-hash, which requires a hash of the target account for local authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberoasting attack
Why it's wrong here
Kerberoasting targets Kerberos service tickets (TGS) encrypted with the service account's password hash, not NTLM challenge/response hashes. The tester would need valid domain credentials and an SPN to request a ticket, then crack it offline. The captured NTLMv2 hash is an authentication exchange by a client, not a TGS ticket, so Kerberoasting cannot leverage it.
- ✓
NTLM relay attack
Why this is correct
In an NTLM relay attack, the tester uses tools like Impacket's ntlmrelayx to capture an NTLMv2 challenge/response and immediately forward it to a target service, making the remote server believe the authentication came from the legitimate user. The attacker never needs the password or to crack the hash; the relayed exchange is accepted as valid proof of identity, enabling unauthorized access to services like SMB, HTTP, or LDAP.
- ✗
SMB relay attack
Why it's wrong here
SMB relay is a specific variant of NTLM relay where the authentication is forwarded to an SMB service. While SMB is a frequent relay target, the generic attack name 'NTLM relay' is more accurate because the same captured NTLMv2 hash can be relayed to LDAP, HTTP, or other protocols. Describing it as only an SMB relay ignores the broader relay capability and the protocol-agnostic nature of the attack.
- ✗
Pass-the-hash attack
Why it's wrong here
Pass-the-hash requires the actual NT hash (MD4 hash of the password) to authenticate directly, usually via tools like Mimikatz or impacket's psexec. The NTLMv2 hash captured during a challenge/response exchange is the client's response to a server challenge, not the NT hash itself, and cannot be replayed for pass-the-hash. Pass-the-hash does not involve relaying a challenge/response to a separate service; it uses a pre-obtained hash to log in.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.