PEN-200 Active Directory Attacks Practice Question
During an internal penetration test you compromise a domain-joined workstation and recover a user's NTLMv2 hash via a forced authentication attempt. SMB signing is enforced on all servers, and the client will not initiate outbound SMB connections. You want to crack the credential offline rather than relay it. Which approach is most appropriate?
⚠ Common exam trap
The trap here is assuming any captured NTLM material can be relayed or passed directly, when a challenge/response pair requires offline cracking and cannot be used as a hash for authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Responder in analyze mode to capture the challenge/response, then run Hashcat with mode 5600 against the captured netntlmv2 hash and a targeted wordlist.
The captured artifact is an NTLMv2 challenge/response, which is only useful for offline cracking. SMB signing prevents relay, and the client's outbound SMB restriction blocks additional capture avenues. Hashcat mode 5600 is the correct cracking mode for netntlmv2, and a targeted wordlist improves efficiency against a real user's password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use ntlmrelayx.py with the --no-smb-server flag to forward the authentication to a domain controller and dump the SAM database.
Why it's wrong here
Relaying to a domain controller over SMB fails because SMB signing is enforced on the servers, and forwarding authentication to a DC does not yield the local SAM. The --no-smb-server flag only disables the embedded SMB listener; it does not bypass signing. This path cannot succeed in the described environment.
- ✗
Use CrackMapExec with the --hash option to spray the netntlmv2 response across the domain and identify where the account is valid.
Why it's wrong here
CrackMapExec's --hash option expects an NT hash or LM:NT pair, not a netntlmv2 challenge/response. Supplying a captured response there will not authenticate. Password spraying also requires a plaintext or NT hash credential, so this approach cannot work with the artifact recovered.
- ✓
Use Responder in analyze mode to capture the challenge/response, then run Hashcat with mode 5600 against the captured netntlmv2 hash and a targeted wordlist.
Why this is correct
NTLMv2 challenge/response pairs are stored in the netntlmv2 format, which Hashcat mode 5600 is designed to crack. Because SMB signing blocks relay and the client will not initiate outbound SMB, offline cracking is the viable path. Capturing in analyze mode avoids poisoning traffic you cannot use and keeps the evidence clean for the report.
- ✗
Run Mimikatz with the sekurlsa::pth module to inject the captured NTLMv2 response into a new logon session and authenticate as the user.
Why it's wrong here
Pass-the-Hash requires an NT hash, not an NTLMv2 challenge/response. sekurlsa::pth consumes an NT hash to create a network logon session. A captured netntlmv2 response cannot be used directly in this module, so the technique does not apply to the artifact that was recovered.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.