Courseiva
Active Directory Attacks →mediumMultiple Choice

PEN-200 Active Directory Attacks Practice Question

During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?

⚠ Common exam trap

The trap here is assuming that any credential extraction tool like Mimikatz or Hashcat can also perform Pass-the-Hash authentication, when in fact only specific modules or tools are designed for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Impacket's psexec.py

Pass-the-Hash requires a tool that can supply an NTLM hash directly during authentication. Impacket's psexec.py is a Python implementation of PsExec that accepts -hashes, enabling authentication to SMB shares with a hash. The other tools either crack hashes offline, harvest credentials, or extract credentials locally, none of which achieve remote authentication with a hash.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hashcat with mode 1000

    Why it's wrong here

    Hashcat with mode 1000 is used to crack NTLM hashes offline by comparing candidate passwords against the hash. It does not perform authentication to remote services; it only recovers plaintext passwords. In this scenario, the goal is to authenticate directly to the file server using the hash, not to crack it first.

  • ✗

    Responder with the -w flag

    Why it's wrong here

    Responder with the -w flag starts a rogue WPAD proxy server to capture credentials, not to authenticate to remote systems using a hash. It is a credential harvesting tool, not a Pass-the-Hash implementation. Using it here would not achieve authentication to the target file server with the recovered hash.

  • ✗

    Mimikatz with the sekurlsa::logonpasswords module

    Why it's wrong here

    Mimikatz's sekurlsa::logonpasswords module extracts credentials from memory on a compromised Windows host. It does not perform Pass-the-Hash authentication to remote SMB services. While Mimikatz can perform Pass-the-Hash via sekurlsa::pth, that module is not listed here, and the question asks for a Linux-based tool.

  • ✓

    Impacket's psexec.py

    Why this is correct

    Impacket's psexec.py supports Pass-the-Hash via the -hashes argument, allowing an attacker to authenticate to SMB services using an NTLM hash without knowing the plaintext password. It constructs the SMB session using the provided LM:NT hash pair, which is precisely the objective in this scenario where only the hash was recovered from a compromised workstation.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.