Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?

⚠ Common exam trap

Watch out — candidates often confuse the tool that captures the handshake (airodump-ng) or the tool that forces the handshake (aireplay-ng) with the tool that actually performs the cryptographic cracking (aircrack-ng), leading them to select a wrong option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aircrack-ng

Aircrack-ng (option D) is the tool in the Aircrack-ng suite specifically designed to crack WPA2 pre-shared keys (PSK) by performing an offline dictionary or brute-force attack against the captured four-way handshake. It uses the handshake data (specifically the EAPOL frames) to derive the Pairwise Master Key (PMK) and verify it against candidate passphrases, making it the correct choice for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    airmon-ng

    Why it's wrong here

    airmon-ng only enables monitor mode on the wireless interface; it never processes the captured handshake or tests passphrases. It is tempting because it is the first Aircrack-ng tool used in a WPA2 assessment, and it would be correct when preparing an adapter to capture frames before airodump-ng runs.

  • ✗

    airodump-ng

    Why it's wrong here

    airodump-ng captures frames and writes the WPA2 handshake to a .cap file, but performs no offline dictionary or brute-force attack against the PMK. It is tempting as the tool that obtains the handshake, and would be correct when scanning channels and capturing the four-way exchange.

  • ✗

    aireplay-ng

    Why it's wrong here

    aireplay-ng injects frames to force clients to reconnect, generating a handshake for capture, but it does not derive the pre-shared key. It is tempting because it accelerates handshake collection, and would be correct when deauthenticating a station so airodump-ng can record the exchange.

  • ✓

    aircrack-ng

    Why this is correct

    Aircrack-ng performs the actual offline cryptanalysis of the captured four-way handshake, deriving the WPA2 pre-shared key by testing candidate passphrases against the MIC. Other suite tools only capture, inject or deauthenticate; aircrack-ng is the cracking component the scenario requires.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.