PEN-200 Active Directory Attacks Practice Question
Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?
⚠ Common exam trap
Candidates often confuse NTLM relaying with credential harvesting. Relaying is a real-time attack that forwards authentication traffic to a target, whereas harvesting involves offline cracking of captured hashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTLM Relay
NTLM Relay involves capturing authentication requests from a client and forwarding them to a target server. If the target server allows NTLM authentication and does not have protections like SMB signing enabled, the server will accept the relayed authentication as if it came from the original user. This allows the attacker to impersonate the user and execute commands or access files on the target server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting is an offline attack against service tickets (TGS). It does not involve relaying authentication traffic between a client and a server. Kerberoasting targets the service account's NTLM hash by requesting a ticket and then cracking it locally, whereas relaying requires active participation in an ongoing authentication flow.
- ✗
DCSync
Why it's wrong here
DCSync is a replication-based attack used to dump domain credentials. It does not involve relaying network traffic between hosts. It exploits the legitimate Active Directory replication protocol to request data, whereas relaying is a network-level attack that intercepts and redirects authentication packets in real-time to impersonate a legitimate user.
- ✓
NTLM Relay
Why this is correct
NTLM Relay is the process of intercepting authentication requests and forwarding them to a target machine. If successful, the attacker gains access to the target host with the privileges of the authenticated user. This attack is highly effective against environments where SMB signing is not enforced on network servers.
- ✗
Golden Ticket
Why it's wrong here
A Golden Ticket is a forged Kerberos TGT. It is a persistence and impersonation technique that does not rely on relaying NTLM authentication traffic. Instead, it uses the KRBTGT hash to create a valid-looking ticket that grants the attacker access to any service within the domain as any user.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.