Courseiva
mediumMultiple Select

PT0-002 Practice Question: Which TWO of the following are common techniques…

Which TWO of the following are common techniques used during a pass-the-hash attack? (Select TWO.)

⚠ Common exam trap

CompTIA often tests the distinction between pass-the-hash and hash cracking: candidates mistakenly think brute-forcing the hash (Option B) is part of the attack, but pass-the-hash reuses the hash as-is, never attempting to reverse it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extracting NTLM hashes from LSASS

Option A is correct because pass-the-hash attacks commonly begin by dumping NTLM password hashes from the LSASS process memory (e.g., with Mimikatz's sekurlsa::logonpasswords or ProcDump), since LSASS caches credential material of logged-on users. Option D is correct because the core of pass-the-hash is reusing a captured NTLM hash without cracking it, typically by injecting it into a process or authentication context (e.g., Mimikatz sekurlsa::pth or Impacket's psexec with -hashes) so the attacker authenticates as the victim over NTLM. Option B is not a pass-the-hash technique because brute-forcing a hash is a cracking attempt to recover the plaintext, which pass-the-hash deliberately avoids. Option C is unrelated, as password spraying tries a few common passwords across many accounts and does not use captured hashes. Option E describes Kerberos ticket abuse (e.g., overpass-the-hash or golden ticket), not the NTLM hash reuse that defines pass-the-hash.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Extracting NTLM hashes from LSASS

    Why this is correct

    LSASS (Local Security Authority Subsystem Service) caches NTLM hashes for interactive and network logons so users don't re-authenticate constantly. An attacker with admin rights can use Mimikatz's sekurlsa::logonpasswords or dump memory with ProcDump to extract these hashes, which are then directly usable for pass-the-hash. This step is essential because PtH relies on having a valid hash rather than the plaintext password.

  • ✗

    Performing a brute-force attack on the hash

    Why it's wrong here

    A brute-force attack attempts to recover the plaintext password by trying billions of candidate passwords against the captured hash, often using tools like John the Ripper or Hashcat. This is hash cracking, not pass-the-hash, which uses the hash itself as a credential to authenticate without ever needing the plaintext. Brute-forcing is also computationally expensive and can be detected, while PtH is stealthier because it skips the cracking step entirely.

  • ✗

    Using a password spray attack

    Why it's wrong here

    A password spray attack is an online guessing technique that tries one or a few commonly used passwords (like 'Winter2024!') across many user accounts to avoid account lockout thresholds. It targets the authentication service directly, not captured credential material, and is a form of credential brute-forcing. Pass-the-hash, by contrast, requires possession of a valid NTLM hash extracted from a system and uses that hash to impersonate the user without any guessing.

  • ✓

    Injecting hashes into a process to authenticate

    Why this is correct

    Injecting a captured hash into a process involves loading the NTLM hash into the memory of a process via tools like Mimikatz with the sekurlsa::pth module, thereby changing the process's security context to impersonate the target user. The injected hash allows the process to successfully complete NTLM challenge-response handshakes with remote services as that user. This is the core execution phase of a pass-the-hash attack, and it enables lateral movement without knowledge of the plaintext password.

  • ✗

    Requesting Kerberos TGS tickets

    Why it's wrong here

    Requesting Kerberos TGS (Ticket Granting Service) tickets is part of kerberoasting, an attack that retrieves service tickets encrypted with a service account's NTLM hash, then cracks the hash offline. This attack targets Kerberos, not the NTLM challenge-response mechanism that pass-the-hash exploits. Additionally, kerberoasting requires a valid domain user account to request the tickets, whereas pass-the-hash uses NTLM hashes extracted from memory and does not rely on Kerberos ticket requests.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.