mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is using Hashcat to crack…
A penetration tester is using Hashcat to crack NTLM hashes obtained from a Windows system. The tester wants to use a rule-based attack to maximize cracking success. Which Hashcat mode should be used for NTLM hashes?
⚠ Common exam trap
Many candidates confuse NTLM hashes (mode 1000) with NetNTLMv1 (mode 5500) or other Windows-related hash types, as candidates often mix up local authentication hashes with network authentication challenge-response hashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-m 1000
Hashcat mode -m 1000 is specifically designated for NTLM hashes, which are the Windows NT LAN Manager hash format stored in the SAM database. A rule-based attack with this mode applies transformation rules to wordlists to generate candidate passwords, maximizing cracking success by leveraging common password patterns and mutations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
-m 1000
Why this is correct
Mode 1000 is the correct hashcat mode for pure NTLM hashes, which are the MD4 digest of the user's password encoded in UTF-16LE and stored in the Windows SAM database or NTDS.dit. This mode directly feeds the raw 32-character hexadecimal NTLM hash into hashcat's cracking algorithms, such as dictionary, rule-based, or brute-force attacks. Selecting any other mode will cause hashcat to parse the hash incorrectly, leading to false negatives or incorrect crack attempts.
- ✗
-m 1100
Why it's wrong here
Mode 1100 is designated for Domain Cached Credentials (DCC), also known as cached domain logons. These are not plain NTLM hashes but a salted and iterated derivative: the hash is computed by passing the NTLM hash through MD4 with the username as a salt, then repeating the MD4 operation for 1024 iterations. Because the transformation includes the username and multiple iterations, attempting to crack a standard NTLM hash with mode 1100 will fail, as hashcat will expect a different hash format and structure.
- ✗
-m 3000
Why it's wrong here
Mode 3000 targets LM hashes, an obsolete Windows authentication mechanism that predates NTLM. LM hashes are derived by splitting the password into two 7-character uppercase halves, padding each with null bytes, and DES-encrypting a fixed constant, making them trivially weak and vulnerable to rainbow tables. NTLM hashes, by contrast, use a single MD4 hash of the UTF-16LE password with no case conversion or split, so they are not compatible with mode 3000 and that mode will not correctly parse an NTLM hash.
- ✗
-m 5500
Why it's wrong here
Mode 5500 is used for NetNTLMv2 challenge-response values captured during network authentication, such as those obtained with Responder or other MITM tools. Unlike a static NTLM hash stored in the SAM, NetNTLMv2 is a challenge-response pair that involves a server challenge and a client response computed from the NTLM hash via HMAC-MD5, along with a timestamp and other data. Cracking a stored NTLM hash with mode 5500 will not work because the input format expects a different structure (with the challenge appended), and the attack is performed on the network protocol exchange rather than the locally stored hash.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.