Why Resetting Local Passwords Blocks Pass-the-Hash Attacks

Identity and Access Management
Answer Correct answer: C — Resetting local passwords generates new hashes that invalidate stolen credentials used in pass-the-hash attacks.

A security administrator recently reset local passwords and the following values were recorded in the system: Which of the following is the security administrator most likely protecting against? - image

  1. Account sharing
  2. Weak password complexity
  3. Pass-the-hash attacks Correct Answer
  4. Password compromise

Community Votes

C
52%
D
48%

52% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Evaluates the relationship between hash invalidation and credential lifecycle management, while trapping candidates who conflate general account breaches with targeted hash replay exploitation.

This scenario tests how periodic credential rotation and secure hashing disrupt unauthorized lateral movement. The page clarifies that updating stored password hashes directly neutralizes previously exfiltrated credential material.

Option D is selected when test-takers overlook that the displayed hash values specifically indicate protection against credential replay rather than broad password theft.

Community Discussion (14 comments)

johnabayot 👍 9 Selected: C
C. Pass the hash attack By resetting the local passwords, the security administrator is changing the hash values of the passwords, which invalidates any previously stolen hashes. This prevents the attacker from using the old hashes to access the system or move laterally across the network. Resetting the local passwords does not protect against password compromise, unless the administrator also ensures that the passwords are stored securely, transmitted over encrypted channels, and protected from phishing or keylogging attacks.
SM9 👍 1 Selected: D
The table is a distractor. Just read the question without the table. Only D makes sense based on what is being asked. The attacker can still take the values from a newly generated table to perform the pass-the-hash attack.
Dapsie 👍 1 Selected: D
The password change action and storing the password hashes are protecting against password compromise
Lipton376 👍 1 Selected: C
C. Pass the hash
Caballer 👍 1 Selected: C
The values provided in the scenario look like hashed representations of passwords. When a security administrator resets local passwords and stores them in a hashed format, it is likely done to protect against pass-the-hash attacks.
francuza 👍 1
its is local users hashes not passed anywhere
subaie503 👍 2 Selected: D
only answer that makes sense
DrakeMallard 👍 3 Selected: C
C. Pass-the-hash attacks Pass-the-hash attacks involve an attacker obtaining hashed passwords from a compromised system and then using those hashes to authenticate to other systems on the network. The use of MD5 hashed passwords (as seen in the provided values) can be vulnerable to pass-the-hash attacks because once the hash is obtained, it can potentially be used to authenticate without needing to crack the password itself. By resetting the local passwords and recording new hashed values, the security administrator is likely aiming to mitigate the risk of pass-the-hash attacks by ensuring that even if an attacker obtains hashed passwords, they will be unable to use them for unauthorized access.
7308365 👍 4
D. Password compromise I think they are just resetting the passwords based on time. All of the accounts are admin accounts so I'm assuming they have admins reset their accounts more frequently than other users. In this situation, the fact that the passwords are hashed doesn't matter because there are programs to crack the hash and changing the hash more frequently doesn't make it any easier/harder for the software to crack said hash... Lack of access to the actual hashes makes pass-the-hash attacks harder.
Benrosan 👍 3 Selected: D
Seems like a password compromise. Admin reset passwords and what we're seeing are simply the new MD5 hashed values
ganymede 👍 3 Selected: D
D. Password compromise
licks0re 👍 4
Is that a protection against pass hash because the passwords are stored in hash format ? I dont think so.. I would go D.
volc7 👍 3 Selected: D
All values are diff. Probably a passed compromise triggered a reset for everyone
Hs1208 👍 3
C. Pass the Hash as the recorded values are in hash representation rather than clear text.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Pass-the-hash attacks rely on attackers capturing and replaying password hashes to authenticate across systems without knowing the plaintext password. By regularly resetting local passwords, the administrator forces the operating system to generate new cryptographic hashes, instantly invalidating any previously stolen hash values. This practice directly breaks the attack chain described in CompTIA’s IAM guidelines, where stale credentials are the primary vector for lateral movement.

Why the Other Options Are Wrong

Account sharing involves multiple users utilizing identical credentials, which password resets do not address. Weak password complexity relates to policy enforcement during creation, not the storage format or rotation cycle shown. While resetting passwords does respond to password compromise, the explicit display of hashed values and the focus on hash invalidation point specifically to disrupting hash-based authentication exploits rather than generic breach remediation.

Community Comment Notes

Several learners noted that rotating hashes renders exfiltrated credential dumps useless, with one stating "changing the hash more frequently doesn't make it any easier/harder" before realizing the exam focuses on hash invalidation over brute-force difficulty. Others correctly observed that "the recorded values are in hash representation rather than clear text," confirming the scenario targets hash replay mechanics. A few debated whether this simply addresses password compromise, but the emphasis on stored hash formats aligns with SY0-601’s pass-the-hash mitigation objectives.

Official Reference

Exam Strategy

When SY0-601 questions highlight stored hash formats alongside credential rotation, immediately map the scenario to lateral movement prevention. Ignore broad breach terminology if the prompt emphasizes cryptographic storage mechanisms, as the exam prioritizes specific attack vectors over general IT hygiene.

Frequently Asked Questions

Why isn't this just protecting against password compromise?

Password compromise is a broad outcome, but the scenario explicitly highlights stored hash values. Rotating these hashes specifically breaks the replay mechanism used in pass-the-hash attacks.

Does storing passwords as hashes prevent pass-the-hash entirely?

No, hashing alone does not stop hash replay, but regular password resets force new hashes, rendering previously stolen hash values useless for authentication.

Related Analysis

← Back to SY0-601 Study Guide