Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester needs to crack a large number of NTLM hashes. They have a wordlist and want to apply common password mutations. Which hashcat option enables the use of a rule file to mutate words?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-r

Hashcat's -r option specifies a rule file that defines transformations (mutation) on dictionary words.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    -r

    Why this is correct

    -r specifies a rule file for rule-based attack, enabling mutation of dictionary words such as appending digits or substituting characters to efficiently crack many hashes. In hashcat, -r loads a file containing rule functions like l (lowercase), u (uppercase), $ (append), s (substitute), applied to each word from a wordlist, generating candidate passwords without storing them all. For a large NTLM hash set, rule-based attacks greatly expand coverage while keeping disk usage minimal, so -r is the correct flag.

  • ✗

    -a 0

    Why it's wrong here

    -a 0 selects pure dictionary attack mode, which uses a wordlist exactly as supplied without any rule-based modifications. In hashcat, this option iterates over each line of the dictionary and hashes it as-is, so it cannot apply transformations like capitalizing or appending numbers to guess more complex NTLM passwords. While it may crack weak credentials, it lacks the rule engine required for an efficient large-scale rule-driven effort.

  • ✗

    -a 6

    Why it's wrong here

    -a 6 is a hybrid attack mode in hashcat that combines a wordlist with a mask, such as -a 6 wordlist.txt ?d?d?d, to append mask-generated characters to the end of each dictionary word. This method does not use rule functions; it only adds a fixed suffix pattern, so it does not mutate the base word in arbitrary ways like a rule-based attack does. Therefore -a 6 would not fulfill the requirement for rule-based cracking.

  • ✗

    -m 1000

    Why it's wrong here

    -m 1000 sets the hash type to NTLM (an MD4-based hash), which is necessary for hashcat to interpret the input correctly and apply any cracking method. However, this option only configures the algorithm and does not enable or invoke rule-based processing; rules still require the -r flag with a rule file. Without -r, using -m 1000 alone would run a default brute-force or dictionary attack, not a rule-based one.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.