PT0-002 Attacks and Exploits Practice Question
A penetration tester wants to crack NTLM hashes obtained from a Windows system. Which Hashcat mode should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-m 1000
Hashcat mode 1000 is for NTLM hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
-m 1000
Why this is correct
-m 1000 is the correct Hashcat mode for NTLM hashes. NTLM hashes are computed as the MD4 digest of the user's password encoded in UTF-16LE, and the raw hash is a 128-bit value. This mode is commonly used when cracking password hashes dumped from the Windows SAM database or via tools like Mimikatz, as it targets the specific algorithm used for legacy Windows authentication. NTLM has a single MD4 round with no salt, which makes it extremely fast to crack on modern GPU hardware.
- ✗
-m 22000
Why it's wrong here
-m 22000 is incorrect because it corresponds to WPA-PBKDF2, the key derivation function used for WPA/WPA2-PSK Wi-Fi networks. In that mode, the pre-shared key is combined with the SSID as a salt and stretched through 4096 iterations of PBKDF2-HMAC-SHA1, which is a deliberately slow process to resist offline attacks. This has nothing to do with Windows NTLM hashes, which use the MD4 hash and do not involve PBKDF2 or WPA handshakes.
- ✗
-m 0
Why it's wrong here
-m 0 is not appropriate here because it specifies raw MD5 hashing, whereas NTLM is built on MD4, not MD5, and the input is the password expressed in UTF-16LE rather than a plain byte string. Feeding an NTLM hash into mode 0 would attempt to crack it as a standard MD5 hash, which will fail because the underlying algorithms and transformations are different. Even though both MD5 and MD4 are fast, legacy MD5 does not match NTLM's construction or bit length.
- ✗
-m 13100
Why it's wrong here
-m 13100 is the Hashcat mode for Kerberos 5 TGS-REP etype 23, which is used to crack Kerberos service tickets encrypted with RC4. This mode targets the hash of a Kerberos ticket that an attacker might capture from a network interception or via a tool like Rubeus or impacket, and it is unrelated to NTLM hashes. While Kerberos and NTLM both exist in Active Directory environments, selecting mode 13100 would try to crack a ticket structure, not the MD4-based NTLM hash.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.