Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

An incident responder is investigating a breach where attackers gained initial access via a phishing email. The email contained a malicious macro that executed a PowerShell script. The script attempted to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. Which of the following techniques is the attacker most likely using, and what is the primary goal?

⚠ Common exam trap

The trap here is conflating credential dumping with Pass-the-Hash; dumping is the theft of credentials, while Pass-the-Hash is the use of those credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential dumping, to obtain plaintext passwords or hashes from memory for further attacks.

The attacker is performing credential dumping from LSASS to harvest credentials. This is a common step after initial access, enabling further attacks like lateral movement or privilege escalation. The other options describe different techniques that either occur after credential dumping or target different components. Therefore, credential dumping is the correct identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pass-the-Hash, to authenticate to other systems using captured NTLM hashes without knowing the plaintext password.

    Why it's wrong here

    Pass-the-Hash involves using captured NTLM hashes for authentication, but the scenario describes extracting credentials from LSASS. While LSASS dumping can yield hashes, the immediate action described is credential extraction, not the subsequent authentication step. The primary goal here is to obtain credentials, not yet to use them for lateral movement.

  • ✓

    Credential dumping, to obtain plaintext passwords or hashes from memory for further attacks.

    Why this is correct

    Credential dumping from LSASS is a common post-exploitation technique to extract plaintext passwords, NTLM hashes, and Kerberos tickets. Attackers use tools like Mimikatz or ProcDump to access LSASS memory. The goal is to harvest credentials that can be used for lateral movement, privilege escalation, or persistence. This matches the scenario's description of extracting credentials from LSASS.

  • ✗

    Golden Ticket attack, to forge Kerberos ticket-granting tickets using the KRBTGT account hash.

    Why it's wrong here

    A Golden Ticket attack requires the KRBTGT account hash, which is typically obtained from a domain controller, not a workstation's LSASS. The scenario involves a compromised workstation via phishing, not a domain controller. While LSASS dumping could yield the KRBTGT hash if on a DC, the scenario specifies a workstation, making this unlikely.

  • ✗

    Kerberoasting, to request service tickets and crack their encryption offline to obtain service account passwords.

    Why it's wrong here

    Kerberoasting targets Kerberos service tickets (TGS) and does not involve LSASS memory extraction. It requires domain user credentials to request tickets for service accounts. The scenario describes direct LSASS access, which is unrelated to Kerberoasting. Thus, this technique does not align with the observed activity.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.