nerdexam
CompTIA

CAS-003 · Question #62

An external penetration tester compromised one of the client organization's authentication servers and retrieved the password database. Which of the following methods allows the penetration tester…

The correct answer is A. Use the pass the hash technique. With passing the hash you can grab NTLM credentials and you can manipulate the Windows logon sessions maintained by the LSA component. This will allow you to operate as an administrative user and not impact the integrity of any of the systems when running your tests.

Enterprise Security Operations

Question

An external penetration tester compromised one of the client organization's authentication servers and retrieved the password database. Which of the following methods allows the penetration tester to MOST efficiently use any obtained administrative credentials on the client organization's other systems, without impacting the integrity of any of the systems?

Options

  • AUse the pass the hash technique
  • BUse rainbow tables to crack the passwords
  • CUse the existing access to change the password
  • DUse social engineering to obtain the actual password

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    18% (5)
  • C
    4% (1)
  • D
    7% (2)

Explanation

With passing the hash you can grab NTLM credentials and you can manipulate the Windows logon sessions maintained by the LSA component. This will allow you to operate as an administrative user and not impact the integrity of any of the systems when running your tests.

Topics

#pass the hash#credential exploitation#penetration testing#authentication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice