Why Resetting Local Passwords Blocks Pass-the-Hash Attacks
A security administrator recently reset local passwords and the following values were recorded in the system: Which of the following is the security administrator most likely protecting against? - 
Community Votes
52% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Evaluates the relationship between hash invalidation and credential lifecycle management, while trapping candidates who conflate general account breaches with targeted hash replay exploitation.
This scenario tests how periodic credential rotation and secure hashing disrupt unauthorized lateral movement. The page clarifies that updating stored password hashes directly neutralizes previously exfiltrated credential material.
Option D is selected when test-takers overlook that the displayed hash values specifically indicate protection against credential replay rather than broad password theft.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Pass-the-hash attacks rely on attackers capturing and replaying password hashes to authenticate across systems without knowing the plaintext password. By regularly resetting local passwords, the administrator forces the operating system to generate new cryptographic hashes, instantly invalidating any previously stolen hash values. This practice directly breaks the attack chain described in CompTIA’s IAM guidelines, where stale credentials are the primary vector for lateral movement.Why the Other Options Are Wrong
Account sharing involves multiple users utilizing identical credentials, which password resets do not address. Weak password complexity relates to policy enforcement during creation, not the storage format or rotation cycle shown. While resetting passwords does respond to password compromise, the explicit display of hashed values and the focus on hash invalidation point specifically to disrupting hash-based authentication exploits rather than generic breach remediation.Community Comment Notes
Several learners noted that rotating hashes renders exfiltrated credential dumps useless, with one stating "changing the hash more frequently doesn't make it any easier/harder" before realizing the exam focuses on hash invalidation over brute-force difficulty. Others correctly observed that "the recorded values are in hash representation rather than clear text," confirming the scenario targets hash replay mechanics. A few debated whether this simply addresses password compromise, but the emphasis on stored hash formats aligns with SY0-601’s pass-the-hash mitigation objectives.Official Reference
Exam Strategy
When SY0-601 questions highlight stored hash formats alongside credential rotation, immediately map the scenario to lateral movement prevention. Ignore broad breach terminology if the prompt emphasizes cryptographic storage mechanisms, as the exam prioritizes specific attack vectors over general IT hygiene.
Frequently Asked Questions
Why isn't this just protecting against password compromise?
Password compromise is a broad outcome, but the scenario explicitly highlights stored hash values. Rotating these hashes specifically breaks the replay mechanism used in pass-the-hash attacks.
Does storing passwords as hashes prevent pass-the-hash entirely?
No, hashing alone does not stop hash replay, but regular password resets force new hashes, rendering previously stolen hash values useless for authentication.