CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
During an incident investigation, an analyst finds that an attacker extracted NTLM password hashes from a compromised workstation's memory and used them directly to authenticate to other systems without ever cracking the passwords. Which technique was used?
- APass-the-hash attack
- BRainbow table attack
- CKerberoasting
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: A. Pass-the-hash attack
A pass-the-hash attack allows an attacker to authenticate to a system using a captured password hash directly, without needing to know or crack the plaintext password.
Why the other options are wrong
- B. Rainbow tables are used to crack hashes into plaintext, not reuse them directly.
- C. Kerberoasting targets service account ticket-granting tickets in Kerberos, not NTLM hash reuse.
- D. Brute-force involves guessing passwords repeatedly, not reusing captured hashes.
Pass-the-Hash
An attack technique where a captured password hash is used to authenticate to systems without decrypting it into plaintext.
- Exploits NTLM authentication weaknesses
- No need to crack the password
- Mitigated by Credential Guard and reducing hash caching
Memory trick: Pass the hash like passing a note — no need to read it, just hand it over.