Courseiva
Attacking Password Hashes →mediumMultiple Choice

GPEN Attacking Password Hashes Practice Question

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

⚠ Common exam trap

A common mix-up: candidates confuse Pass-the-Hash with other hash-based attacks like Kerberoasting or Golden Ticket, which require different prerequisites and have different goals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-the-Hash (PtH) using Mimikatz sekurlsa::pth

Pass-the-Hash allows an attacker to authenticate using the NTLM hash without cracking it. Tools like Mimikatz can inject the hash into a session, enabling lateral movement or access to resources. Other options involve cracking or forging tickets, which are different attack vectors. The scenario emphasizes using the hash directly, making Pass-the-Hash the correct technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Golden Ticket attack using the KRBTGT hash

    Why it's wrong here

    A Golden Ticket requires the KRBTGT account's NTLM hash to forge a Kerberos TGT, granting domain-wide access. While it uses an NTLM hash, it is not a Pass-the-Hash technique and requires the KRBTGT hash specifically, not a user's hash. It is used for persistence and privilege escalation, not for simple authentication with a user's hash.

  • ✓

    Pass-the-Hash (PtH) using Mimikatz sekurlsa::pth

    Why this is correct

    Pass-the-Hash leverages the NTLM hash to authenticate to remote services without knowing the plaintext password. Mimikatz's sekurlsa::pth command injects the hash into a new session, enabling access to SMB shares or other services that accept NTLM authentication. This is a core technique in penetration testing, as it bypasses the need to crack the hash.

  • ✗

    Kerberoasting to request a service ticket

    Why it's wrong here

    Kerberoasting targets service accounts with SPNs to obtain a service ticket encrypted with the service account's NTLM hash, which is then cracked offline. It does not allow direct authentication using an NTLM hash. This technique requires a different set of privileges and is used to escalate privileges or move laterally, not to authenticate with a stolen hash directly.

  • ✗

    Rainbow table lookup to recover the plaintext password

    Why it's wrong here

    Rainbow tables are precomputed hash chains used to crack unsalted password hashes offline. They do not enable authentication; they recover the plaintext password, which can then be used for authentication. This is a cracking method, not a direct authentication technique, and it requires significant storage and time, and is ineffective against salted hashes.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.