Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester needs to perform an online brute-force attack against an SSH service. Which tool is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hydra

Hydra is a versatile online brute-force tool supporting many protocols including SSH.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hydra

    Why this is correct

    Hydra is a network authentication brute-force tool designed to perform online attacks against live services. It actively submits username and password guesses to a running protocol such as SSH, HTTP, or FTP over the network, making it the correct choice for an online SSH brute-force attempt. Hydra supports many protocols, can employ custom wordlists, and offers concurrency controls to speed up the attack while respecting service limitations.

  • ✗

    John the Ripper

    Why it's wrong here

    John the Ripper is an offline password cracker that operates on password hash files, not live network services. It does not send authentication attempts to a remote server, so it cannot perform an online brute-force attack against SSH. Instead, John the Ripper takes a captured hash and tries to recover the plaintext password by guessing candidates and comparing their hashes locally.

  • ✗

    CrackMapExec

    Why it's wrong here

    CrackMapExec is a post-exploitation and network enumeration tool focused on Windows Active Directory environments. It authenticates via protocols such as SMB, LDAP, and WinRM, but it is not designed to perform online brute-force attacks against SSH services. While CrackMapExec can validate credentials, its protocol support and purpose are misaligned with an SSH brute-force task.

  • ✗

    Hashcat

    Why it's wrong here

    Hashcat is a GPU-accelerated offline hash-cracking tool that works on local hash values, not on a live network service. It does not interact with an SSH server or submit passwords over the network, so it cannot be used for online brute-force attacks. Hashcat is highly effective for cracking stolen password hashes but is the wrong tool when the target is a reachable SSH service.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.