exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 473 discussion

Actual exam question from CompTIA's SY0-501
Question #: 473
Topic #: 1
[All SY0-501 Questions]

A security analyst is mitigating a pass-the-hash vulnerability on a Windows infrastructure.
Given the requirement, which of the following should the security analyst do to MINIMIZE the risk?

  • A. Enable CHAP
  • B. Disable NTLM
  • C. Enable Kerebos
  • D. Disable PAP
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Elb
Highly Voted 5 years, 5 months ago
B. The NTLM protocol uses one or both of two hashed password values, both of which are also stored on the server (or domain controller), and which through a lack of salting are password equivalent, meaning that if you grab the hash value from the server, you can authenticate without knowing the actual password.
upvoted 32 times
Iyake
4 years, 7 months ago
BRAVO FOR THIS EXPLANATION ELB
upvoted 1 times
...
who__cares123456789___
4 years, 6 months ago
PAP is clear text so no need to pass me the Hashish!
upvoted 3 times
...
...
hakeyann
Most Recent 4 years, 5 months ago
Thank you
upvoted 1 times
...
AndyT8686
4 years, 6 months ago
NTLM (New Technology LAN Manager): Used for authenticating in a Windows domain, was replaced by Kerberos for the most part. a. NTMLv2: Is the most common form used, is somewhat insecure.
upvoted 1 times
...
DookyBoots
4 years, 9 months ago
NTLM remains vulnerable to the pass the hash attack, which is a variant on the reflection attack which was addressed by Microsoft security update MS08-068. For example, Metasploit can be used in many cases to obtain credentials from one machine which can be used to gain control of another machine.[3][25] The Squirtle toolkit can be used to leverage web site cross-site scripting attacks into attacks on nearby assets via NTLM.[26] https://en.wikipedia.org/wiki/NT_LAN_Manager
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...