nerdexam
CompTIA

PT0-003 · Question #91

During an assessment, a penetration tester obtains an NTLM hash from a legacy Windows machine. Which of the following tools should the penetration tester use to continue the attack?

The correct answer is D. CrackMapExec. CrackMapExec (CME) is a post-exploitation tool commonly used for lateral movement, credential validation, and network enumeration in Windows environments. It supports using NTLM hashes to authenticate (pass-the-hash) across systems, making it ideal for continuing an attack with a

Submitted by haru.x· Mar 6, 2026Post-exploitation and Lateral Movement

Question

During an assessment, a penetration tester obtains an NTLM hash from a legacy Windows machine. Which of the following tools should the penetration tester use to continue the attack?

Options

  • AResponder
  • BHydra
  • CBloodHound
  • DCrackMapExec

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    13% (3)
  • C
    4% (1)
  • D
    75% (18)

Explanation

CrackMapExec (CME) is a post-exploitation tool commonly used for lateral movement, credential validation, and network enumeration in Windows environments. It supports using NTLM hashes to authenticate (pass-the-hash) across systems, making it ideal for continuing an attack with a

Topics

#NTLM hashes#pass-the-hash#CrackMapExec#lateral movement

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice