Courseiva
Active Directory Attacks →mediumMultiple Choice

PEN-200 Active Directory Attacks Practice Question

Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?

⚠ Common exam trap

Candidates often confuse NTLM relaying with credential harvesting. Relaying is a real-time attack that forwards authentication traffic to a target, whereas harvesting involves offline cracking of captured hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTLM Relay

NTLM Relay involves capturing authentication requests from a client and forwarding them to a target server. If the target server allows NTLM authentication and does not have protections like SMB signing enabled, the server will accept the relayed authentication as if it came from the original user. This allows the attacker to impersonate the user and execute commands or access files on the target server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting is an offline attack against service tickets (TGS). It does not involve relaying authentication traffic between a client and a server. Kerberoasting targets the service account's NTLM hash by requesting a ticket and then cracking it locally, whereas relaying requires active participation in an ongoing authentication flow.

  • ✗

    DCSync

    Why it's wrong here

    DCSync is a replication-based attack used to dump domain credentials. It does not involve relaying network traffic between hosts. It exploits the legitimate Active Directory replication protocol to request data, whereas relaying is a network-level attack that intercepts and redirects authentication packets in real-time to impersonate a legitimate user.

  • ✓

    NTLM Relay

    Why this is correct

    NTLM Relay is the process of intercepting authentication requests and forwarding them to a target machine. If successful, the attacker gains access to the target host with the privileges of the authenticated user. This attack is highly effective against environments where SMB signing is not enforced on network servers.

  • ✗

    Golden Ticket

    Why it's wrong here

    A Golden Ticket is a forged Kerberos TGT. It is a persistence and impersonation technique that does not rely on relaying NTLM authentication traffic. Instead, it uses the KRBTGT hash to create a valid-looking ticket that grants the attacker access to any service within the domain as any user.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.