Courseiva
Active Directory Attacks →easyMultiple Choice

PEN-200 Active Directory Attacks Practice Question

Which of the following conditions is required to execute a successful Pass-the-Hash (PtH) attack against a target workstation?

⚠ Common exam trap

Candidates often assume that any captured NTLM hash can be used to authenticate against any target. You must specifically possess a hash belonging to an account with local administrative rights on the destination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The NTLM hash must correspond to an account with local administrative rights.

Pass-the-Hash relies on the fact that NTLM authentication uses the hash of a password rather than the password itself. If an attacker gains the NTLM hash of a user who has local administrative rights on a target, they can authenticate as that user. This is a primary method for lateral movement within an AD environment, allowing attackers to escalate privileges across hosts without ever needing to know the user's actual cleartext password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The target machine must have Kerberos disabled.

    Why it's wrong here

    PtH is an NTLM-based attack and does not depend on the status of Kerberos on the target. As long as the target allows NTLM authentication, the attack can proceed. Kerberos and NTLM often coexist in Active Directory environments, and disabling Kerberos is not a prerequisite for conducting NTLM-based lateral movement.

  • ✗

    The attacker must possess the cleartext password of the target user.

    Why it's wrong here

    The entire purpose of a Pass-the-Hash attack is to bypass the need for a cleartext password. By using the NTLM hash directly in the authentication process, the attacker mimics the legitimate credential negotiation, effectively authenticating to the target without the overhead or risk of obtaining the cleartext password.

  • ✓

    The NTLM hash must correspond to an account with local administrative rights.

    Why this is correct

    To achieve lateral movement or privilege escalation via PtH, the captured hash must belong to an account that has the necessary permissions on the target system. Without local administrative rights, the attacker may authenticate successfully but will remain restricted to the low-privileged environment of the captured user.

  • ✗

    The target machine must be a Domain Controller.

    Why it's wrong here

    PtH is commonly used for lateral movement between workstations and servers, not just Domain Controllers. In fact, directly targeting a DC with PtH is often restricted by tiered administration models. The attack is most effective when moving laterally across the network to compromise additional hosts or escalate local system privileges.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.