CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

During an incident investigation, an analyst finds that an attacker extracted NTLM password hashes from a compromised workstation's memory and used them directly to authenticate to other systems without ever cracking the passwords. Which technique was used?

  1. APass-the-hash attack
  2. BRainbow table attack
  3. CKerberoasting
  4. DBrute-force attack
Show answer & explanation

Correct answer: A. Pass-the-hash attack

A pass-the-hash attack allows an attacker to authenticate to a system using a captured password hash directly, without needing to know or crack the plaintext password.

Why the other options are wrong

  • B. Rainbow tables are used to crack hashes into plaintext, not reuse them directly.
  • C. Kerberoasting targets service account ticket-granting tickets in Kerberos, not NTLM hash reuse.
  • D. Brute-force involves guessing passwords repeatedly, not reusing captured hashes.

Pass-the-Hash

An attack technique where a captured password hash is used to authenticate to systems without decrypting it into plaintext.

  • Exploits NTLM authentication weaknesses
  • No need to crack the password
  • Mitigated by Credential Guard and reducing hash caching

Memory trick: Pass the hash like passing a note — no need to read it, just hand it over.

More Threats, Vulnerabilities, and Mitigations questions