GCIH Attacking Passwords Practice Question
An attacker has obtained a set of NTLM hashes from a compromised workstation and now wants to use them to authenticate to other systems in the domain without cracking them. Which two of the following conditions are necessary for a successful Pass-the-Hash attack? (Choose two.)
⚠ Common exam trap
The trap here is thinking Pass-the-Hash requires administrative rights or the plaintext password, but it only requires a valid hash and NTLM-enabled target.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The target systems must accept NTLM authentication.
Pass-the-Hash requires that the target systems accept NTLM authentication and that the compromised hash belongs to an account with logon rights on those systems. Without these, the attack cannot proceed. Administrative privileges, plaintext passwords, and domain controller status are not necessary conditions, making them incorrect choices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target systems must be domain controllers.
Why it's wrong here
Pass-the-Hash can be used against any system that accepts NTLM authentication, not just domain controllers. Workstations and member servers are also vulnerable. While domain controllers are high-value targets, they are not a requirement for the attack to work. This condition is too restrictive and thus incorrect.
- ✓
The target systems must accept NTLM authentication.
Why this is correct
Pass-the-Hash relies on the NTLM authentication protocol. If target systems are configured to only accept Kerberos authentication, the attack will fail. Therefore, NTLM must be enabled and permitted on the target systems for the hash to be used directly for authentication. This is a fundamental requirement for the attack to succeed.
- ✗
The attacker must know the plaintext password associated with the hash.
Why it's wrong here
Pass-the-Hash specifically allows authentication without knowing the plaintext password. The entire point is to use the hash directly. Requiring the plaintext would defeat the purpose of the attack. Therefore, this condition is not necessary and is incorrect.
- ✓
The NTLM hash must correspond to a user account with logon rights on the target systems.
Why this is correct
For Pass-the-Hash to succeed, the compromised hash must belong to a user account that is authorized to log on to the target systems. If the account lacks logon rights, authentication will fail even with a valid hash. Thus, the account's permissions are critical, making this condition necessary.
- ✗
The attacker must have administrative privileges on the target systems.
Why it's wrong here
Administrative privileges are not required to perform Pass-the-Hash; the attacker only needs the hash of a user account that has access to the target. The privileges of that user determine what can be done after authentication. However, administrative rights on the local machine are not a prerequisite for the authentication attempt itself.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.