Courseiva
Password Attacks →mediumMultiple Choice

PEN-200 Password Attacks Practice Question

You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?

⚠ Common exam trap

Students commonly attempt a direct pass-the-hash attack using a captured NetNTLMv2 challenge-response hash, failing to realize these cannot be used like local NTLM password hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attempt to relay the hash to another system that has SMB signing disabled.

NetNTLMv2 hashes are challenge-response hashes, not password hashes. They cannot be used in a pass-the-hash attack. Instead, they must be cracked offline to obtain the plaintext password or relayed to a target that supports NTLM authentication. Recognizing the distinction between NetNTLM and NTLM is a critical concept in OSCP-level testing, as it prevents the misuse of these credentials during lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attempt to relay the hash to another system that has SMB signing disabled.

    Why this is correct

    NetNTLMv2 hashes are highly effective when used in SMB relay attacks. If the target system has SMB signing disabled, an attacker can relay the hash to authenticate as the victim, gaining immediate access to the system without ever needing to know the user's actual password.

  • ✗

    Use the hash directly in a pass-the-hash attack against an RDP session.

    Why it's wrong here

    NetNTLMv2 hashes are not compatible with pass-the-hash (PtH) techniques, which require NTLM hashes. Attempting to use a NetNTLMv2 hash in a PtH tool will fail because the protocol expects the challenge-response hash, which is specific to a single authentication attempt, not a persistent credential like an NTLM hash.

  • ✗

    The hash can be used to authenticate to the Domain Controller for domain persistence.

    Why it's wrong here

    A captured NetNTLMv2 hash is for a specific, transient authentication session. It cannot be used to 'authenticate' as a domain entity in the way a TGT or a persistent credential could. It must be relayed or cracked to gain any further utility, making it a poor choice for persistence.

  • ✗

    Directly inject the hash into the LSASS process to create a new user session.

    Why it's wrong here

    Injecting into the LSASS process requires NTLM hashes or cleartext credentials, not challenge-response hashes. Injecting a NetNTLMv2 hash would be ineffective because the LSASS process expects a different format and would not recognize the challenge-response string as a valid credential for creating a new user session.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.