Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

Why are 'Pass-the-Hash' (PtH) attacks effective for pivoting in a Windows environment?

⚠ Common exam trap

Candidates often assume that Pass-the-Hash attacks require cracking the NTLM hash to recover the original plaintext user password, confusing PtH with credential cracking methods like brute-forcing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Because NTLM authentication does not require the password itself.

PtH attacks leverage the NTLM hash directly to authenticate, bypassing the need for the plaintext password. Because Windows stores these hashes in LSASS for single-sign-on capabilities, an attacker who gains administrative rights can extract them and reuse them to access other systems in the domain. This is a fundamental risk in environments where users have local admin rights on their workstations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Because they force a password reset on the target.

    Why it's wrong here

    PtH does not involve resetting or changing passwords. It is an authentication bypass technique that uses existing credential material. If it triggered a password reset, it would be highly visible to users and administrators, making it a failed, noisy attack rather than a successful stealthy pivot.

  • ✓

    Because NTLM authentication does not require the password itself.

    Why this is correct

    The NTLM authentication protocol is designed to verify identity using a challenge-response mechanism based on the user's hash. As long as the attacker has the valid hash, they can participate in the challenge-response process just like the legitimate user, gaining unauthorized access to the network resources.

  • ✗

    Because they only work on Linux-based domain controllers.

    Why it's wrong here

    Pass-the-Hash is a Windows-centric attack specifically targeting the NTLM authentication mechanism. It is not designed for Linux-based systems, which typically use different authentication protocols like Kerberos or SSH keys. The vulnerability exists within the Windows OS architecture, not in Linux domain controller environments.

  • ✗

    Because the hash is always encrypted with AES-256.

    Why it's wrong here

    NTLM hashes are not encrypted with AES-256; they are derived using the MD4 algorithm. The effectiveness of PtH does not depend on the strength of the encryption used to store the hash, but rather on the design of the NTLM protocol which accepts the hash as authentication material.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.