GCIH Attacking Passwords Practice Question
During an internal penetration test, you capture SMB traffic between a user workstation and a file server on the same Layer 2 segment. The captured exchange shows the client sending an authentication request containing a username and a challenge/response value, but no cleartext password. You want to recover the user's cleartext password offline using a wordlist. Which attack technique should you apply to the captured challenge/response pair?
⚠ Common exam trap
The trap here is assuming that a captured NTLM challenge/response can be relayed back to the same server or used directly as an NT hash, when in fact it must be cracked offline or relayed to a different target.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform an offline dictionary attack against the captured NTLMv2 challenge/response using a tool such as Hashcat with mode 5600.
The captured exchange is a NetNTLMv2 authentication, which exposes a challenge/response rather than a cleartext password or NT hash. To recover the cleartext password, an attacker performs an offline dictionary or brute-force attack against that response using a tool configured for NetNTLMv2, such as Hashcat mode 5600. This avoids further interaction with the target and does not trigger account lockouts on the server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Extract the user's NT hash from the capture and submit it to a Pass-the-Hash tool to authenticate to the file server.
Why it's wrong here
The capture contains a NetNTLMv2 challenge/response, not the user's NT hash. The NT hash is a stored secret used in NTLM authentication internally, and it is not transmitted on the wire during a normal SMB logon. Treating the captured response as an NT hash will not work for Pass-the-Hash, which requires the actual NT hash.
- ✗
Decrypt the SMB session with the server's machine account key to reveal the user's password from the encrypted payload.
Why it's wrong here
The SMB session payload does not contain the user's password, and the server machine account key does not decrypt user authentication material. NTLM authentication proves knowledge of the password through a challenge/response computation; the password itself is never sent, so decryption cannot reveal it. Offline cracking of the captured response is the appropriate path.
- ✓
Perform an offline dictionary attack against the captured NTLMv2 challenge/response using a tool such as Hashcat with mode 5600.
Why this is correct
The captured material is an NTLMv2 challenge/response (NetNTLMv2), and Hashcat mode 5600 is designed specifically to crack NetNTLMv2 hashes offline against a wordlist. Because the challenge/response is derived from the user's password, guessing passwords and recomputing the response lets you recover the cleartext password without touching the live server.
- ✗
Replay the captured challenge/response value directly to the file server to authenticate as the user without cracking it.
Why it's wrong here
Replaying a captured NetNTLMv2 challenge/response to the same server generally fails because the server issues a fresh random challenge for each authentication, so the response is tied to the original challenge. This is why relay attacks target a different service rather than replaying to the originating server, and why offline cracking is required to recover the password here.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.