🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 58 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During an internal penetration test you captured the NTLM hash of the local Administrator account from several Windows 10 workstations using an SMB relay attack. The customer's endpoint detection rules quarantine any new executables written to disk, so you must avoid dropping files on the target. Which approach allows you to execute commands on one of the compromised hosts while honoring this restriction?

  • Use PsExec with the stolen hash to install its service and open an interactive shell over SMB.

  • Forge a Golden Ticket for the Administrator account and authenticate via Kerberos to obtain a remote shell.

  • Leverage Impacket's wmiexec.py to perform a Pass-the-Hash attack over WMI and run commands in memory on the remote host.

  • Start a password-guessing attack against the local Administrator account until the clear-text password is discovered.

Certified Ethical Hacker (CEH)
System Hacking Phases and Attack Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot