A penetration tester is able to capture the ntlm challengere - CompTIA Pentest+ PT0-003

Question

A penetration tester is able to capture the NTLM challenge-response traffic between a client and a server.
Which of the following can be done with the pcap to gain access to the server?

Answers
  1. correct
Explanation

Correct Answer: D. Utilize a pass-the-hash attack.

When a penetration tester captures NTLM challenge-response traffic, they can extract the NTLM hash of a user's password. NTLM authentication does not require knowing the plaintext password—attackers can reuse the hash in what is called a Pass-the-Hash (PtH) attack to authenticate to the server.

  • Pass-the-Hash (PtH) allows an attacker to authenticate using the hash itself instead of cracking the password.
  • This technique is commonly used against Windows environments, where NTLM hashes can be passed to network services like SMB or RDP for access.

Why the Other Options Are Incorrect:

Perform vertical privilege escalation.

  • Vertical privilege escalation means gaining higher privileges (e.g., from user to admin/root) on a system.

  • Simply capturing NTLM challenge-response traffic does not automatically grant higher privileges—you still need valid authentication.

Incorrect because capturing NTLM traffic does not, by itself, elevate privileges.

Replay the captured traffic to the server to recreate the session.

  • NTLM challenge-response authentication includes a nonce (random number) generated by the server.

  • This means you cannot simply replay the captured traffic to establish a session because the server will issue a different challenge each time.

Incorrect because NTLM authentication uses a challenge-response mechanism that prevents direct replay attacks.

Use John the Ripper to crack the password.

  • NTLM hashes can be cracked using John the Ripper or Hashcat, but this is not the most efficient way to gain access.

  • Pass-the-Hash is faster and does not require cracking the password—it simply reuses the hash for authentication.
  • Cracking NTLM hashes can take significant time, depending on the password complexity.

Incorrect because cracking the hash is unnecessary when Pass-the-Hash can be used directly.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered