Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester needs to automate a series…

A penetration tester needs to automate a series of web application attacks against a login page to identify weak credentials. Which tool is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hydra

Hydra (option B) is the most appropriate tool because it is a dedicated online password-cracking utility that automates credential-guessing attacks against login forms and services, supporting protocols like HTTP-POST and HTTP-GET with configurable username/password lists and threading. For a penetration test targeting weak credentials on a web login page, Hydra's ability to script repeated authentication attempts makes it purpose-built for this task. Nmap (A) is a port scanner and service/version detector, not a credential brute-forcer. Burp Suite (C) is a web proxy and testing platform that can facilitate manual or Intruder-based attacks but is not primarily an automated credential-cracking tool. Wireshark (D) is a packet analyzer used for traffic capture and inspection, not for launching authentication attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network reconnaissance tool that excels at host discovery, port scanning, and service/version enumeration. Although the Nmap Scripting Engine (NSE) includes brute-force scripts like http-form-brute and ssh-brute, these are auxiliary components and not the tool's primary focus; they also lack Hydra's parallelized, protocol-specific optimization and large wordlist handling. Therefore, Nmap would not be the correct choice for automating a web application credential brute-force attack.

  • ✓

    Hydra

    Why this is correct

    Hydra is a dedicated network login cracker designed specifically for high-speed parallel brute-force attacks against numerous protocols, including HTTP/HTTPS forms, FTP, SMB, SSH, and others. It supports custom username and password wordlists, flexible parameterization, and multi-threading to maximize attempts per minute, and it can handle web-specific features like session cookies and HTTP basic/digest authentication. These capabilities make Hydra the ideal automated tool for credential brute-forcing a web application.

  • ✗

    Burp Suite

    Why it's wrong here

    Burp Suite is an integrated web application security testing platform whose primary value lies in intercepting, modifying, and replaying HTTP requests via its proxy, repeater, and Intruder tools. While Intruder can cycle payloads for brute-force attempts, it is a general-purpose attack engine that requires per-request manual tuning and runs in a GUI, making it less streamlined and less network-optimized for pure credential attacks than a command-line tool like Hydra. Thus, Burp Suite would not be the preferred choice for automating large-scale brute-force credential testing.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a protocol analyzer that passively captures and dissects network packets for troubleshooting or security investigation. It provides no capability to generate or inject login attempts, and it cannot send credentials to a web application's authentication endpoint. Since the task requires actively automating brute-force attempts rather than inspecting network traffic, Wireshark is completely unsuitable for this purpose.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.