Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?

⚠ Common exam trap

Candidates often pick only one or two options and miss the requirement for a comprehensive approach. They may forget LAPS, which is critical for preventing lateral movement via local admin credential reuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Credential Guard on all workstations and servers.

Pass-the-Hash exploits the way NTLM stores password hashes in memory. By limiting the scope of where privileged accounts can authenticate and restricting the use of legacy protocols like NTLM in favor of Kerberos, organizations can significantly shrink the attack surface. Implementing Credential Guard provides an additional layer of hardware-based isolation that prevents the extraction of these hashes from memory, effectively neutralising the primary mechanism that attackers rely on for lateral movement within a domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Credential Guard on all workstations and servers.

    Why this is correct

    Credential Guard uses virtualization-based security to isolate secrets in a protected container. By preventing access to the LSA process memory, it stops attackers from extracting NTLM hashes or Kerberos tickets, which are the fundamental building blocks for Pass-the-Hash and Pass-the-Ticket attacks, significantly hardening the host against lateral movement.

  • ✓

    Disable NTLM authentication and force Kerberos usage.

    Why this is correct

    NTLM is inherently vulnerable to relay and capture-based attacks because it relies on challenge-response mechanisms that do not provide mutual authentication. Disabling NTLM forces the use of Kerberos, which is much more secure, does not expose static password hashes in the same way, and prevents the simple PtH attack vector.

  • ✓

    Implement Local Administrator Password Solution (LAPS).

    Why this is correct

    LAPS ensures that the local administrator password on every machine in the domain is unique and randomly generated. This prevents an attacker who gains access to one machine from using the same local admin credentials to compromise every other machine in the enterprise, effectively stopping simple password-based lateral movement.

  • ✗

    Increase the minimum password length requirement to 20 characters.

    Why it's wrong here

    While strong passwords are a good security policy, they do not prevent Pass-the-Hash attacks. PtH works by using the already-hashed version of the password stored in memory; the actual password complexity is irrelevant to the attack, as the attacker never needs to crack the underlying password to succeed.

  • ✗

    Regularly scan for and remove all local user accounts.

    Why it's wrong here

    Removing local accounts does not stop PtH, as the attack often targets domain-level accounts that are logged into the compromised machine. Furthermore, removing local accounts can break essential system functionality and administrative capabilities, creating operational instability without providing a meaningful reduction in the risk of lateral movement via hash reuse.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.