Courseiva
Password Attacks →mediumMultiple Choice

PEN-200 Password Attacks Practice Question

You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?

⚠ Common exam trap

Test-takers frequently assume that obtaining an NTLM hash guarantees successful lateral movement, forgetting that legacy protocol restrictions or hardening can block pass-the-hash entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.

Pass-the-hash (PtH) relies on the fact that authentication protocols like NTLM require the hash itself rather than the cleartext password. Understanding this mechanism is vital because it allows attackers to impersonate users without needing to crack complex passwords. The technique effectively bypasses the need for plaintext credentials, making it a staple for lateral movement in internal penetration tests when local administrator or service account access is achieved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The target system must have the Kerberos pre-authentication disabled for the user account.

    Why it's wrong here

    Kerberos pre-authentication is unrelated to NTLM-based pass-the-hash attacks. While disabling it facilitates AS-REP roasting, it does not enable pass-the-hash functionality. NTLM authentication occurs independently of Kerberos mechanisms, meaning the state of pre-authentication on the domain controller has no bearing on whether an NTLM hash can be used successfully.

  • ✗

    The victim machine must have the 'Restricted Admin' mode enabled in the RDP configuration.

    Why it's wrong here

    Restricted Admin mode for RDP is a specific security feature designed to prevent credential exposure during remote sessions. While it relates to how credentials are handled, it is not a prerequisite for conducting a pass-the-hash attack, which typically utilizes tools like Mimikatz or Impacket to inject hashes into an existing session.

  • ✓

    The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.

    Why this is correct

    Pass-the-hash depends on the target service or system accepting NTLM authentication. If an environment is strictly configured to use Kerberos-only authentication and NTLM is disabled via Group Policy or security settings, the hash will fail to authenticate because the system will reject the NTLM challenge-response sequence entirely.

  • ✗

    The target machine must be running a version of Windows older than Windows Server 2012.

    Why it's wrong here

    Pass-the-hash is not limited to legacy Windows versions. While newer versions have introduced protections like Credential Guard, the fundamental vulnerability inherent to the NTLM protocol remains present across all modern versions of Windows, provided the protocol itself is not explicitly disabled within the domain or local security policy.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.