PT0-002 Attacks and Exploits Practice Question
During an internal penetration test, the tester wants to relay captured NTLM authentication to a server to gain access. Which tool from the Impacket suite is specifically designed for NTLM relay attacks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ntlmrelayx
ntlmrelayx is the Impacket tool for relaying NTLM authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec (CME) is a modular post-exploitation toolkit for credential reuse, lateral movement, and reconnaissance across many hosts, but it requires you to already possess valid credentials or hashes. It does not intercept an in-flight NTLM authentication handshake or forward it to another server, so it cannot act as a relay. Its SMB/HTTP modules either authenticate directly or dump credentials, making it a consumer of authentication material rather than a relay attacker.
- ✓
ntlmrelayx
Why this is correct
ntlmrelayx is the core Impacket tool built specifically for NTLM relay: it listens for SMB, HTTP, HTTPS, and other authentication attempts, then relays that challenge-response handshake to a chosen target such as SMB, LDAP, MSSQL, or other protocols. It can automatically perform SMB-signing and EPA checks, dump secrets, create users, or execute commands as the impersonated user, and it optionally integrates with Responder for coerced authentication. This is why it is the dedicated answer for relaying rather than just capturing.
- ✗
Metasploit
Why it's wrong here
Metasploit's auxiliary modules include SMB/HTTP capture and hash-dumping functionality, but its capture modules mainly log and hash-crack rather than transparently forwarding a live authentication handshake to an arbitrary target. There is no mature, purpose-built NTLM relay module in mainstream Metasploit that matches ntlmrelayx's protocol coverage (e.g., HTTP-to-SMB, SMB-to-LDAP with signing/EPA checks). Using Metasploit for relay would require hacky script injection or external plugins, making it the wrong choice versus a dedicated relay framework.
- ✗
Responder
Why it's wrong here
Responder is a poisoning tool that spoofs LLMNR/NBT-NS/mDNS responses to trick victims into sending NTLMv1/NTLMv2 hashes to the attacker, but it stops short of relay. By default, Responder's rogue SMB/HTTP server simply captures the challenge-response and stores it for offline cracking or pass-the-hash reuse; it never forwards that authentication conversation to a real server. To relay, you must disable SMB/HTTP in Responder and feed the network sink to ntlmrelayx, proving Responder alone is only the hash-capture half of the attack.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.