GPEN Attacking Password Hashes Practice Question
A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?
⚠ Common exam trap
The trap here is assuming that an extracted NT hash must be cracked before it can be used for authentication, when in fact the hash itself can be replayed to access resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-the-Hash using the NT hash directly in an authentication request
Pass-the-Hash is the correct technique because Windows authentication protocols accept the NT hash as a valid credential. An attacker who extracts the hash can use it to authenticate to remote services without cracking the plaintext. The other options either aim at password recovery or rely on different credential material, such as Kerberos tickets, which are not present in this scenario. The key distinction is that Pass-the-Hash uses the hash directly for authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-the-Ticket by injecting a forged Kerberos TGT into memory
Why it's wrong here
Pass-the-Ticket involves stealing or forging a Kerberos ticket and injecting it into a session to authenticate. It requires a valid TGT or TGS, not an NT hash. While it can achieve lateral movement, it is a different attack path that depends on Kerberos artifacts, not the SAM hash. The scenario supplies an NT hash and asks for direct authentication, so Pass-the-Ticket is not the appropriate technique.
- ✗
Kerberoasting the target service account to obtain its TGS ticket
Why it's wrong here
Kerberoasting targets service accounts with registered SPNs by requesting a TGS ticket and cracking it offline. It does not use an NT hash from SAM and does not provide immediate authentication to a file share. This technique is used to escalate privileges or move laterally by cracking service account passwords, but it is unrelated to the extracted NT hash. The scenario already provides a credential; Kerberoasting would be an unnecessary detour.
- ✓
Pass-the-Hash using the NT hash directly in an authentication request
Why this is correct
Pass-the-Hash exploits the fact that Windows authentication protocols accept the NT hash itself as proof of identity, so a tester can authenticate to SMB, WMI, or other services without cracking the hash. The NT hash is the actual credential material stored in SAM or LSASS, so it can be used directly with tools like Mimikatz or Impacket. This is the correct approach here because the scenario explicitly requires authentication without the plaintext password.
- ✗
Rainbow table lookup against the NT hash to recover the plaintext password
Why it's wrong here
Rainbow tables map precomputed hash chains to plaintext passwords, but they only work if the hash is unsalted and the table covers the password space. NT hashes are unsalted, so rainbow tables are feasible, but they do not directly authenticate to a remote server. The scenario asks for authentication to a file share, not password recovery, so a rainbow table lookup is the wrong objective. It also requires significant storage and time, making it impractical for immediate access.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.