Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is using Hashcat to crack NTLM hashes obtained from a Windows domain controller. Which hash mode should the tester specify for NTLM hashes?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-m 1000

Hashcat uses mode -m 1000 for NTLM hashes. Mode 0 is for MD5, mode 13100 is for Kerberoast, and mode 22000 is for WPA2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -m 22000

    Why it's wrong here

    Hashcat mode 22000 is specifically designed for WPA/WPA2/WPA3 handshakes captured during wireless assaults, such as from a pcap or hccapx file. NTLM hashes are Windows authentication credentials extracted from memory or the SAM database, not network handshakes. Feeding an NTLM hash to this mode would cause hashcat to parse it as a PMKID or EAPOL structure, resulting in a parsing error or a zero-crack outcome.

  • ✗

    -m 0

    Why it's wrong here

    Hashcat mode 0 targets raw MD5 hashes, which are produced by simple crypt() implementations or legacy MD5-based systems. NTLM hashes, by contrast, are calculated with MD4 over a UTF-16LE encoded password, a fundamentally different algorithm. Using -m 0 would force hashcat to run MD5 candidate generation, so the NTLM digest would never match, and the crack would fail despite correct password guesses.

  • ✗

    -m 13100

    Why it's wrong here

    Mode 13100 is reserved for Kerberos 5 TGS-REP hashes, which are obtained by Kerberoasting Active Directory service accounts. NTLM hashes are either stored in the local SAM or extracted from LSASS and are not related to Kerberos ticket structures. Attempting to crack an NTLM hash with -m 13100 would make hashcat interpret the 32-hex-character NTLM digest as a TGS ticket hash, causing an incorrect salt/handling and no successful crack.

  • ✓

    -m 1000

    Why this is correct

    Hashcat mode 1000 is the exact and documented mode for NTLM hashes, which are generated by computing MD4 of the password's UTF-16LE representation. When a penetration tester extracts NTLM hashes from a Windows target—via Samdump, Mimikatz, or an NTDS.dit dump—this is the mode to use for offline password cracking. Specifying -m 1000 correctly tells hashcat to apply the NTLM algorithm, enabling effective dictionary, rule-based, or mask attacks.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.