GPEN Attacking Password Hashes Practice Question
Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?
⚠ Common exam trap
Candidates often mistakenly believe NTLM is insecure primarily because it is 'too old'. The actual technical reasons involve its fundamental design flaws, specifically the lack of salting and lack of mutual authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of mutual authentication allows for relay attacks.
NTLM is inherently insecure because it is a challenge-response protocol that does not provide mutual authentication, making it susceptible to relay attacks. Furthermore, the NTLM hash is stored in a format that does not include a salt, allowing for the use of precomputed tables. Finally, because NTLM hashes are treated as the 'equivalent' of a password in many contexts, once stolen, they can be reused without needing to crack them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Lack of mutual authentication allows for relay attacks.
Why this is correct
NTLM does not require the server to prove its identity to the client. This architectural flaw enables attackers to capture a client's authentication challenge and relay it to another server, effectively masquerading as the user without ever having to crack the password or hash.
- ✓
The NTLM hash format does not utilize a salt.
Why this is correct
Because NTLM hashes do not include a unique salt for each user, identical passwords result in identical hashes across the domain. This facilitates the use of precomputed rainbow tables, which allow an attacker to look up the plaintext password for a hash almost instantly.
- ✗
NTLM requires a connection to a Domain Controller for every login.
Why it's wrong here
NTLM is designed to work in disconnected or local environments and does not require a Domain Controller for every authentication request. It uses the local SAM database or cached credentials, which is actually a security risk in itself because it keeps credentials stored on the local host.
- ✗
The protocol uses hard-coded encryption keys for every session.
Why it's wrong here
NTLM uses a session-based challenge-response mechanism, not hard-coded keys. The weakness lies in the protocol's design and the lack of salt in the hash, rather than the use of static encryption keys for the entire session. The primary issue is the hash vulnerability to offline cracking.
- ✓
NTLM hashes are vulnerable to pass-the-hash attacks.
Why this is correct
In NTLM, the hash is used as the credential itself rather than a password. If an attacker captures the NTLM hash, they can present it to other network services to authenticate as the user, completely bypassing the need for the plaintext password or the cracking of the hash.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.