PEN-200 Password Attacks Practice Question
You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?
⚠ Common exam trap
Test-takers frequently assume that obtaining an NTLM hash guarantees successful lateral movement, forgetting that legacy protocol restrictions or hardening can block pass-the-hash entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.
Pass-the-hash (PtH) relies on the fact that authentication protocols like NTLM require the hash itself rather than the cleartext password. Understanding this mechanism is vital because it allows attackers to impersonate users without needing to crack complex passwords. The technique effectively bypasses the need for plaintext credentials, making it a staple for lateral movement in internal penetration tests when local administrator or service account access is achieved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target system must have the Kerberos pre-authentication disabled for the user account.
Why it's wrong here
Kerberos pre-authentication is unrelated to NTLM-based pass-the-hash attacks. While disabling it facilitates AS-REP roasting, it does not enable pass-the-hash functionality. NTLM authentication occurs independently of Kerberos mechanisms, meaning the state of pre-authentication on the domain controller has no bearing on whether an NTLM hash can be used successfully.
- ✗
The victim machine must have the 'Restricted Admin' mode enabled in the RDP configuration.
Why it's wrong here
Restricted Admin mode for RDP is a specific security feature designed to prevent credential exposure during remote sessions. While it relates to how credentials are handled, it is not a prerequisite for conducting a pass-the-hash attack, which typically utilizes tools like Mimikatz or Impacket to inject hashes into an existing session.
- ✓
The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.
Why this is correct
Pass-the-hash depends on the target service or system accepting NTLM authentication. If an environment is strictly configured to use Kerberos-only authentication and NTLM is disabled via Group Policy or security settings, the hash will fail to authenticate because the system will reject the NTLM challenge-response sequence entirely.
- ✗
The target machine must be running a version of Windows older than Windows Server 2012.
Why it's wrong here
Pass-the-hash is not limited to legacy Windows versions. While newer versions have introduced protections like Credential Guard, the fundamental vulnerability inherent to the NTLM protocol remains present across all modern versions of Windows, provided the protocol itself is not explicitly disabled within the domain or local security policy.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.