PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aircrack-ng
Aircrack-ng is the tool within the suite that performs dictionary or brute-force attacks on captured WPA/WPA2 handshakes to recover the PSK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
airtun-ng
Why it's wrong here
airtun-ng creates virtual tunnel interfaces (e.g., a TAP device) that allow arbitrary IP packets to be injected into a wireless stream and de-capsulated from monitored traffic. It is useful for man-in-the-middle attacks or routing traffic through a WLAN, but it performs no mathematical key recovery. Because WEP/WPA cracking depends exclusively on analyzing captured packets or handshakes with aircrack-ng, airtun-ng is not the correct tool for this task.
- ✓
aircrack-ng
Why this is correct
aircrack-ng is the core cryptanalysis tool that takes captured 802.11 traffic and recovers wireless encryption keys. For WEP, it applies the PTW or KoreK/FMS attacks once enough IVs have been collected; for WPA/WPA2, it performs a dictionary or brute-force attempt against the MIC computed during the 4-way EAPOL handshake. It validates the correct key by matching the passphrase-specific PMK to the handshake's MIC, making it the exact utility needed to complete the cracking objective.
- ✗
airodump-ng
Why it's wrong here
airodump-ng operates as a channel-scanning packet sniffer that captures raw 802.11 frames, displaying live BSSIDs, clients, and beacon/probe metrics while writing data to pcap files. It is essential early in an assessment to identify target access points and signal strength and to verify whether a handshake has been captured, but it has no built-in ability to compute or test cryptographic keys. The captured frames it produces must be fed into aircrack-ng; therefore it is a reconnaissance/capture tool, not a cracker.
- ✗
aireplay-ng
Why it's wrong here
aireplay-ng generates and injects wireless frames to manipulate the network, such as sending deauthentication packets to knock clients offline and force them to re-associate, thereby revealing the 4-way handshake. It also injects ARP request packets to quickly fill up the IV pool on a WEP network, making a subsequent WEP crack feasible. These actions only create or foment the traffic conditions that aircrack-ng needs; aireplay-ng itself never attempts to figure out or derive the encryption key.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.