PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hydra
Hydra is a versatile online brute-force tool that supports many protocols, including SSH.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec is a post-exploitation and Active Directory assessment tool that automates tasks across SMB, WinRM, and other Windows-centric protocols, but it does not include a module for performing dictionary attacks against SSH. Its credential-spraying capabilities are aimed at network shares and domain services, not at authenticating to remote SSH daemons. Using it here would be misapplying a lateral-movement utility, not a network service brute-forcer.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is an offline password cracker that operates on pre-captured hash values, such as those from /etc/shadow or Windows SAM files. It does not connect to live services; instead, it compares candidate passwords against hash digests locally. Since an SSH dictionary attack requires sending username/password pairs to an active SSH server over the network, John the Ripper is fundamentally unsuited for this task.
- ✗
Hashcat
Why it's wrong here
Hashcat is a high-performance offline hash-cracking tool that leverages GPU acceleration to recover passwords from hash samples. It works by generating candidate hashes and comparing them to a target hash, entirely on local hardware, with no network interaction. Because the penetration tester needs to test live SSH credentials against a remote service, Hashcat cannot perform this direct online brute-force attack—it only speeds up recovery of already-obtained hashes.
- ✓
Hydra
Why this is correct
Hydra is the correct choice because it is a network login cracking tool designed specifically for online brute-force and dictionary attacks against live services. It supports SSH and dozens of other protocols, and its parallelized connection handling allows rapid testing of password lists against a remote target. Hydra sends actual authentication requests to the SSH daemon, making it the only listed option capable of performing an active dictionary attack against a running service.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.