Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?

⚠ Common exam trap

Many exam-takers confuse airodump-ng (capture tool) with aircrack-ng (cracking tool) or aireplay-ng (injection tool), leading them to pick a tool that cannot actually capture the handshake.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

airodump-ng

Airodump-ng (option D) is the correct tool for capturing the four-way handshake because it passively monitors wireless traffic and can save captured packets to a file (e.g., .cap or .pcap). The four-way handshake occurs during the WPA/WPA2 authentication process between a client and an access point, and airodump-ng's ability to filter on a specific channel and BSSID allows the tester to isolate and record the handshake frames for offline cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aircrack-ng

    Why it's wrong here

    aircrack-ng is an offline key-cracking tool that consumes previously captured packet files, not a live packet sniffer. It uses dictionary or brute-force methods to recover WEP keys or WPA/WPA2 passphrases from a .cap/.pcap file, but it cannot receive or decode the radio signal needed to intercept an EAPOL handshake. Without a separate capture utility to supply the handshake, aircrack-ng has no input to work with, so selecting it for the capture phase would be a process error.

  • ✗

    aireplay-ng

    Why it's wrong here

    aireplay-ng is a frame injection utility that can transmit deauthentication frames to disconnect a client, which encourages the client to reconnect and generate a new four-way handshake. While this is a critical step in forcing a handshake, aireplay-ng's role ends at transmission; it does not include a capture engine to record the resulting EAPOL frames. The test would require a simultaneous sniffer on monitor mode, such as airodump-ng, to actually save the handshake.

  • ✗

    Airmon-ng

    Why it's wrong here

    Airmon-ng places a wireless interface into monitor mode but does not capture packets itself; it lacks the packet-capture engine needed to intercept the four-way handshake. It is tempting because it is the standard tool for enabling monitor mode on a Wi-Fi adapter, which is a prerequisite step before using a sniffer like airodump-ng to capture the handshake.

  • ✓

    airodump-ng

    Why this is correct

    airodump-ng is the dedicated packet capture tool in the aircrack-ng suite, capable of placing the wireless interface into monitor mode and recording raw 802.11 frames to a pcap file. It actively hops channels, probes for access points, and lists associated clients, and it specifically captures the EAPOL four-way handshake frames when a client associates or reconnects. Its output is the direct input for aircrack-ng's offline cracking, making it the correct choice for this capture stage.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.