โ† All EJPT Flashcard Decks

Pivoting and Lateral Movement Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Pivoting and Lateral Movement flashcards as text
  1. What technique does 'Pass-the-Hash' exploit to authenticate to Windows services without knowing the plaintext password?

    Answer: Using the captured NTLM hash directly for authentication

    Pass-the-Hash abuses NTLM's challenge-response protocol by supplying the captured hash directly, since NTLM does not require the plaintext password.

  2. Which tool is commonly used for Pass-the-Hash attacks to get a shell on a remote Windows machine over SMB?

    Answer: pth-winexe

    pth-winexe is a modified version of winexe that accepts NTLM hashes directly, enabling remote command execution over SMB without a plaintext password.

  3. During lateral movement, a pentester discovers a Windows service account password hash. To move laterally using WMI, which Impacket script is most appropriate?

    Answer: wmiexec.py

    Impacket's wmiexec.py executes commands on remote Windows hosts via WMI, a stealthier alternative to psexec that doesn't drop a service binary.

  4. What network protocol does PsExec primarily use to move laterally between Windows hosts?

    Answer: SMB (port 445)

    PsExec creates a service on the target by uploading an executable over SMB's admin share (ADMIN$), then starts it remotely.

  5. Which Metasploit module can dump password hashes from a compromised Windows host to facilitate lateral movement?

    Answer: post/windows/gather/hashdump

    The hashdump post module extracts NTLM password hashes from a Windows host's SAM database, which can then be used for Pass-the-Hash attacks.

  6. A pentester has valid credentials for a Windows domain account. Which technique allows them to execute commands on a remote Windows host using those credentials without a pre-existing shell?

    Answer: PsExec lateral movement via SMB

    PsExec-style lateral movement uses valid credentials to authenticate over SMB, upload a service binary, and execute commands on the remote host.

  7. When enumerating a newly reached internal subnet through a pivot, which Metasploit scanner quickly identifies live hosts?

    Answer: auxiliary/scanner/discovery/udp_sweep

    The udp_sweep scanner sends UDP packets to identify live hosts on a subnet, useful for quick discovery when routed through a pivot.