Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is conducting an internal network assessment and wants to capture NTLMv2 hashes from Windows hosts without sending any authentication traffic. Which tool and attack technique should the tester use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Responder with LLMNR/NBT-NS/mDNS poisoning

Responder poisons LLMNR/NBT-NS/mDNS to trick hosts into sending NTLM hashes to the attacker, capturing them without the attacker needing to authenticate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Responder with LLMNR/NBT-NS/mDNS poisoning

    Why this is correct

    Responder is the correct tool because it actively listens for LLMNR, NBT-NS, and mDNS name-resolution queries broadcast by Windows hosts when DNS lookups fail. By replying with a spoofed response that claims to be the requested host, Responder forces the victim to initiate an SMB authentication handshake to the attacker, sending an NTLMv2 hash in the process. This hash can then be cracked offline with hashcat or relayed with ntlmrelayx, and the attack works without any prior credentials or access to the target system.

  • ✗

    Metasploit's hashdump module

    Why it's wrong here

    Metasploit's hashdump module is a post-exploitation tool, not a credential-capture mechanism. It requires the attacker to already have administrative or SYSTEM-level access to a compromised Windows machine because it reads the local SAM database through low-level API calls. In an unauthenticated internal assessment, where the goal is to capture credentials from network traffic, hashdump is irrelevant because it provides no way to intercept or trigger an authentication challenge over the wire.

  • ✗

    Hashcat with a wordlist attack

    Why it's wrong here

    Hashcat is an offline password-cracking utility that operates on hash files that have already been obtained, such as NTLMv2 captures from Responder or NTDS.dit dumps. It does not have any network capture capabilities, so it cannot interact with LLMNR, NBT-NS, mDNS, or any other live protocol. Without a previously acquired hash, running a wordlist attack against an empty or nonexistent input is impossible, making it a post-capture step rather than a method for initially acquiring credentials.

  • ✗

    Bettercap with ARP spoofing

    Why it's wrong here

    Bettercap with ARP spoofing places the attacker in line for network traffic by poisoning the ARP cache of the target and gateway, but simply rerouting packets does not elicit an NTLMv2 challenge-response. To capture hashes, the redirected traffic must include SMB authentication attempts, and modern defenses like SMB signing or Kerberos can thwart passive extraction. Unlike Responder, ARP spoofing does not actively impersonate a name-query request to force a client to authenticate; it can be detected via ARP monitoring and is not a reliable way to just grab NTLM hashes in an internal assessment.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.