🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 58 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During an internal penetration test you compromise a Windows workstation and, with Responder, capture the domain administrator's NTLMv2 hash over SMB. Cracking the hash is unlikely to succeed before the engagement ends, but the environment still allows NTLM authentication. Which technique will let you open an interactive shell on another domain-joined server without first recovering the clear-text password?

  • Forge a Golden Ticket for the administrator by generating a counterfeit krbtgt ticket and injecting it into your session.

  • Use a pass-the-hash attack with an SMB execution tool such as Impacket's psexec.py to authenticate using the captured NTLM hash.

  • Request and crack the administrator's service tickets through Kerberoasting, then reuse the recovered keys to log in.

  • Conduct a password-spraying campaign across domain hosts with the administrator username and a shortlist of common passwords.

Certified Ethical Hacker (CEH)
System Hacking Phases and Attack Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot