Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester wants to crack NTLM hashes obtained from a Windows domain. Which hashcat mode should the tester use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-m 1000

Hashcat mode 1000 is for NTLM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -m 22000

    Why it's wrong here

    Hashcat mode 22000 is specifically designed for WPA-PBKDF2-PMKID and EAPOL hashes, which are captured from Wi-Fi handshakes, not from Windows authentication attempts. Since NTLM hashes are derived from the MD4 of the user's password in UTF-16LE format, using mode 22000 would force the tool to attempt cracking a WPA-style key derivation against NTLM data, producing false negatives or parsing errors. This mode is completely irrelevant to the password hash format obtained in a typical Active Directory compromise.

  • ✗

    -m 13100

    Why it's wrong here

    Mode 13100 in Hashcat targets Kerberos TGS-REP hashes (etype 23), which are obtained through Kerberoasting attacks against service principal names (SPNs). These hashes are created by encrypting a service ticket with the service account's NTLM hash, but the resulting structure is fundamentally different from a standalone NTLM hash that you would extract from a SAM database or LSASS dump. Attempting to crack NTLM hashes with mode 13100 would fail because the input format for TGS-REP hashes includes the Kerberos ticket fields, not the raw 32-hex-character NTLM digest.

  • ✗

    -m 0

    Why it's wrong here

    Hashcat mode 0 is intended for raw MD5 hashes, such as those generated by simple web application password storage or Unix crypt implementations that use plain MD5. NTLM hashes are not MD5; they are computed using the MD4 algorithm (specifically, MD4 of the password encoded as UTF-16LE), which is a distinct cryptographic hash function. Supplying NTLM hashes to mode 0 would cause Hashcat to treat them as 32-hex-character MD5 digests, and the resulting crack attempts would never produce valid passwords because the underlying hash algorithm and encoding are wrong.

  • ✓

    -m 1000

    Why this is correct

    Hashcat mode 1000 is the correct choice for NTLM hashes, which are the standard credential material extracted from Windows SAM files, NTDS.dit, or memory dumps. These hashes are computed by first converting the password to UTF-16LE and then applying the MD4 hash algorithm, a process unique to Windows authentication. Mode 1000 tells Hashcat to treat each hash as a 32-character hexadecimal NTLM digest, enabling efficient dictionary, rule-based, or brute-force attacks specifically tailored to this format, including pass-the-hash and offline cracking scenarios.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.