adplus-dvertising
frame-decoration

Question

What is the objective of pass-the-hash attacks in penetration testing?

a.

To capture active hashes from authenticated sessions

b.

To add arbitrary hosts to a system’s hosts files

c.

To perform on-path attacks by changing DNS configurations

d.

To replicate the functionality of PsExec

Answer: (a).To capture active hashes from authenticated sessions Explanation:The objective of pass-the-hash attacks in penetration testing is to capture active hashes from authenticated sessions, allowing the attacker to impersonate the user.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What is the objective of pass-the-hash attacks in penetration testing?

Similar Questions

Discover Related MCQs

Q. How can mitm6 be used in a DNS attack?

Q. What does LSASS.exe stand for in the context of pass-the-hash attacks?

Q. Which port is commonly associated with Windows Remote Desktop Protocol (RDP)?

Q. In the context of Apple's Remote Desktop (ARD), how do penetration testers often use ARD?

Q. What is the primary advantage of VNC as a remote desktop tool in penetration testing?

Q. How does DNS attack tool mitm6 exploit a Windows DNS server?

Q. What is a potential disadvantage of using fileless malware in penetration testing?

Q. How can a penetration tester schedule a task on a Windows system using the command line?

Q. What is one common method of exploiting SSH vulnerabilities?

Q. How can long-term access to systems be achieved by exploiting SSH keys?

Q. What is the primary focus of testing network segmentation in the context of penetration testing?

Q. What is a method used by tools allowing VLAN hopping?

Q. What is the purpose of tools like TruffleHog in the context of penetration testing?

Q. Where are unintentionally exposed secret keys frequently found?

Q. What is the primary purpose of post-exploit attacks in penetration testing?

Q. What is the primary purpose of dictionary attacks in penetration testing?

Q. What is a common technique in password cracking when targeting a specific organization?

Q. What is the purpose of rainbow tables in password cracking?

Q. When might cross-compiling be used in penetration testing?

Q. What is the primary focus of horizontal escalation attacks in privilege escalation?