Courseiva
Advanced Password Attacks →mediumMultiple Choice

GPEN Advanced Password Attacks Practice Question

During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?

⚠ Common exam trap

Candidates often confuse SMB signing with password hashing algorithms, assuming that stronger hashes like NTLMv2 prevent relay attacks automatically. However, hashing strength only protects against offline brute-forcing, not active network relaying.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The target machine has disabled SMB signing, allowing challenge-response reuse.

SMB relaying succeeds when message signing is disabled on the target server, allowing an attacker to intercept authentication requests and forward them to another machine. GPEN candidates must understand that signing protects the integrity of SMB sessions. Without it, session hijacking and relaying become trivial threats within local area networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The target machine enforces mandatory SMB signing across all network shares.

    Why it's wrong here

    Mandatory SMB signing prevents relay attacks because the target validates message integrity, so the captured authentication cannot be forwarded. It is tempting because signing is a hardening control, but relaying succeeds only where SMB signing is disabled or not required.

  • ✓

    The target machine has disabled SMB signing, allowing challenge-response reuse.

    Why this is correct

    Disabling SMB signing permits valid authentication responses captured from one victim machine to be forwarded directly to the target system. The target accepts the relayed session because it does not cryptographically verify the message origin or session keys.

  • ✗

    The user account used for authentication has a blank password stored.

    Why it's wrong here

    Blank passwords affect offline cracking speed and local login security but do not dictate whether network relay attacks succeed. Relay attacks target the authentication protocol state machine and session integrity mechanisms rather than password complexity.

  • ✗

    Kerberos protocol is exclusively enforced for all domain controller communications.

    Why it's wrong here

    Forcing pure Kerberos authentication eliminates NTLM fallback and prevents NTLM relaying entirely due to ticket timestamps and mutual authentication. However, the scenario specifically asks what makes relaying feasible, making the absence of Kerberos enforcement the enabler.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.