PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?
⚠ Common exam trap
Many exam-takers confuse airodump-ng (capture tool) with aircrack-ng (cracking tool) or aireplay-ng (injection tool), leading them to pick a tool that cannot actually capture the handshake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
airodump-ng
Airodump-ng (option D) is the correct tool for capturing the four-way handshake because it passively monitors wireless traffic and can save captured packets to a file (e.g., .cap or .pcap). The four-way handshake occurs during the WPA/WPA2 authentication process between a client and an access point, and airodump-ng's ability to filter on a specific channel and BSSID allows the tester to isolate and record the handshake frames for offline cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aircrack-ng
Why it's wrong here
aircrack-ng is an offline key-cracking tool that consumes previously captured packet files, not a live packet sniffer. It uses dictionary or brute-force methods to recover WEP keys or WPA/WPA2 passphrases from a .cap/.pcap file, but it cannot receive or decode the radio signal needed to intercept an EAPOL handshake. Without a separate capture utility to supply the handshake, aircrack-ng has no input to work with, so selecting it for the capture phase would be a process error.
- ✗
aireplay-ng
Why it's wrong here
aireplay-ng is a frame injection utility that can transmit deauthentication frames to disconnect a client, which encourages the client to reconnect and generate a new four-way handshake. While this is a critical step in forcing a handshake, aireplay-ng's role ends at transmission; it does not include a capture engine to record the resulting EAPOL frames. The test would require a simultaneous sniffer on monitor mode, such as airodump-ng, to actually save the handshake.
- ✗
Airmon-ng
Why it's wrong here
Airmon-ng places a wireless interface into monitor mode but does not capture packets itself; it lacks the packet-capture engine needed to intercept the four-way handshake. It is tempting because it is the standard tool for enabling monitor mode on a Wi-Fi adapter, which is a prerequisite step before using a sniffer like airodump-ng to capture the handshake.
- ✓
airodump-ng
Why this is correct
airodump-ng is the dedicated packet capture tool in the aircrack-ng suite, capable of placing the wireless interface into monitor mode and recording raw 802.11 frames to a pcap file. It actively hops channels, probes for access points, and lists associated clients, and it specifically captures the EAPOL four-way handshake frames when a client associates or reconnects. Its output is the direct input for aircrack-ng's offline cracking, making it the correct choice for this capture stage.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.