Courseiva
Network Attacks And Defense StrategieshardMultiple ChoiceObjective-mapped

CND Network Attacks And Defense Strategies Practice Question

An attacker performs a pass-the-hash attack to move laterally across an enterprise network using compromised NTLM hashes. The security architecture team wants to implement host-based mitigations to render harvested NTLM hashes unusable for authentication. Which Windows security feature should be enabled?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Windows Defender Credential Guard utilizing Virtualization-based Security (VBS).

Credential Guard utilizes virtualization-based security (VBS) to isolate secrets (such as NTLM hashes and Kerberos tickets) so that they cannot be stolen or reused even if the LSASS process is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enforce User Account Control (UAC) with highest privilege elevation prompts.

    Why it's wrong here

    UAC governs local administrative elevation, not the reuse of harvested NTLM password hashes.

  • Enable Windows Defender Credential Guard utilizing Virtualization-based Security (VBS).

    Why this is correct

    Credential Guard isolates NTLM hashes and Kerberos tickets in a secure virtualized environment.

  • Configure Windows Defender Exploit Guard with Network Protection enabled.

    Why it's wrong here

    Exploit Guard and Network Protection block connections to malicious C2 IP addresses, not hash reuse.

  • Deploy BitLocker Drive Encryption with TPM 2.0 hardware backing on all endpoints.

    Why it's wrong here

    BitLocker protects data-at-rest against physical theft, not pass-the-hash attacks.

About these practice questions

Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.