GPEN Escalation and Exploitation Practice Question
You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?
⚠ Common exam trap
The trap here is believing the plaintext password must be recovered before an NTLM hash can be used for authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a pass-the-hash attack using the extracted NTLM hash to authenticate to remote SMB services.
NTLM authentication treats possession of the hash as sufficient proof of identity, so the extracted local administrator hash can be supplied directly to tools that establish SMB or WMI sessions. Because that local account is reused across workstations, pass-the-hash grants access to many systems immediately, with no cracking step and no dependency on the plaintext password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the hash as input to an offline brute-force tool to recover the plaintext password.
Why it's wrong here
Offline cracking attempts to recover the original password from the hash, which is exactly what the scenario says is unnecessary. It also may fail if the password is long or complex. The question asks for authentication without cracking, and pass-the-hash achieves that directly, so brute forcing is both slower and contrary to the stated goal.
- ✗
Kerberoast service accounts to obtain crackable service ticket hashes.
Why it's wrong here
Kerberoasting targets service accounts with registered SPNs and requests service tickets that can be cracked offline. It does not use a local administrator NTLM hash and does not authenticate to remote SMB services. Recommending it confuses two distinct credential attacks and ignores the reusable local admin hash that the scenario already provides.
- ✓
Perform a pass-the-hash attack using the extracted NTLM hash to authenticate to remote SMB services.
Why this is correct
Pass-the-hash exploits the fact that NTLM authentication accepts the hash itself as proof of identity, so the plaintext password is unnecessary. Tools such as Impacket's psexec or wmiexec accept an LM:NT hash pair and establish an authenticated session. Because the local administrator credential is reused, this yields access to many workstations without cracking the hash.
- ✗
Run a relay attack with Responder to capture and forward NetNTLM authentications.
Why it's wrong here
Relaying captures and forwards authentications from other hosts; it does not use a hash you already possess to log in. It also requires a victim to authenticate to a controlled endpoint and often needs SMB signing disabled. Because the scenario asks how to authenticate with an extracted hash, relaying misidentifies the objective and the required conditions.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.