Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During an internal penetration test, the tester wants to relay captured NTLM authentication to a server to gain access. Which tool from the Impacket suite is specifically designed for NTLM relay attacks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ntlmrelayx

ntlmrelayx is the Impacket tool for relaying NTLM authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CrackMapExec

    Why it's wrong here

    CrackMapExec (CME) is a modular post-exploitation toolkit for credential reuse, lateral movement, and reconnaissance across many hosts, but it requires you to already possess valid credentials or hashes. It does not intercept an in-flight NTLM authentication handshake or forward it to another server, so it cannot act as a relay. Its SMB/HTTP modules either authenticate directly or dump credentials, making it a consumer of authentication material rather than a relay attacker.

  • ✓

    ntlmrelayx

    Why this is correct

    ntlmrelayx is the core Impacket tool built specifically for NTLM relay: it listens for SMB, HTTP, HTTPS, and other authentication attempts, then relays that challenge-response handshake to a chosen target such as SMB, LDAP, MSSQL, or other protocols. It can automatically perform SMB-signing and EPA checks, dump secrets, create users, or execute commands as the impersonated user, and it optionally integrates with Responder for coerced authentication. This is why it is the dedicated answer for relaying rather than just capturing.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit's auxiliary modules include SMB/HTTP capture and hash-dumping functionality, but its capture modules mainly log and hash-crack rather than transparently forwarding a live authentication handshake to an arbitrary target. There is no mature, purpose-built NTLM relay module in mainstream Metasploit that matches ntlmrelayx's protocol coverage (e.g., HTTP-to-SMB, SMB-to-LDAP with signing/EPA checks). Using Metasploit for relay would require hacky script injection or external plugins, making it the wrong choice versus a dedicated relay framework.

  • ✗

    Responder

    Why it's wrong here

    Responder is a poisoning tool that spoofs LLMNR/NBT-NS/mDNS responses to trick victims into sending NTLMv1/NTLMv2 hashes to the attacker, but it stops short of relay. By default, Responder's rogue SMB/HTTP server simply captures the challenge-response and stores it for offline cracking or pass-the-hash reuse; it never forwards that authentication conversation to a real server. To relay, you must disable SMB/HTTP in Responder and feed the network sink to ntlmrelayx, proving Responder alone is only the hash-capture half of the attack.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.