mediumMultiple Choice
PT0-002 Practice Question: During an internal penetration test, a tester…
During an internal penetration test, a tester captures a NetNTLMv2 hash via an SMB relay attack. The target network does not enforce SMB signing. What is the most effective next step to gain access to a remote server?
⚠ Common exam trap
Test-takers frequently confuse NetNTLMv2 with NTLM hashes, assuming pass-the-hash works with any hash type, when in fact pass-the-hash requires the raw NTLM hash (from LSASS or a dump) and not the challenge-response variant captured via relay.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Relay the captured hash to authenticate to another server.
Since SMB signing is not enforced, the tester can relay the captured NetNTLMv2 hash directly to another server without needing to crack it. This works because the relay attack forwards the authentication challenge-response to a target server, allowing the tester to authenticate as the victim user without knowing the plaintext password. This is the most effective step because it provides immediate access without the time and resource cost of offline cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Crack the hash offline using a dictionary attack.
Why it's wrong here
Offline dictionary cracking of a captured NetNTLMv2 challenge-response is computationally expensive because each password candidate must be converted into a response through the NTLMv2 derivation, which involves multiple MD5 HMAC operations. Even with a strong wordlist or rule-based attack, success depends on password complexity, making it slow and uncertain. In an internal test where SMB signing is not enforced, relaying the captured exchange to a target server yields direct authentication without any offline computation, so cracking is neither the most efficient nor the most reliable next step.
- ✓
Relay the captured hash to authenticate to another server.
Why this is correct
This is the correct approach because the captured NetNTLMv2 challenge-response can be forwarded to a target server as part of an SMB authentication sequence. When SMB signing is not enforced, the target server cannot detect that the relayed response is not associated with the original client, so it accepts the authentication as if it came from the legitimate user. The tester can then gain access to file shares, services, or even remote code execution depending on the privileges of the captured user account, and this bypasses the need to crack the password.
- ✗
Perform a pass-the-hash attack using the captured hash.
Why it's wrong here
Pass-the-hash attacks require a Windows NTLM hash (the MD4 hash of the password) that is stored in the SAM database or memory; the captured NetNTLMv2 challenge-response is not the same thing—it is a derived key computed during the challenge-response exchange. Using a NetNTLMv2 value in a pass-the-hash tool like Mimikatz will fail because the tool needs the actual NTLM hash to compute a fresh response for a new challenge. For this reason, the captured NetNTLMv2 exchange is only usable via relaying to an active session, not for replaying the hash itself.
- ✗
Use the hash to perform an LLMNR poisoning attack.
Why it's wrong here
LLMNR poisoning is an attack that causes a victim to send authentication attempts to the tester by spoofing name resolution for LLMNR/NetBIOS queries; once the tester has already captured a hash, the poisoning stage is complete. The captured hash is the output of that attack, not an input to it, so trying to "use" it for poisoning is conceptually backwards. Furthermore, the hash itself is used for other purposes such as relaying or offline cracking, while LLMNR poisoning is a means to obtain credentials in the first place, not a method to leverage them.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.