PT0-002 Vulnerability Discovery and Analysis Practice Question
A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hydra
Hydra is a fast online brute-force tool that supports many protocols including SSH.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat
Why it's wrong here
Hashcat is a pure offline password recovery tool: it cracks raw dumped password hashes (e.g., NTLM, bcrypt, SHA-512) using CPU/GPU vectorization. It cannot send TCP SYN packets, open an SSH session, or iterate through username/password pairs against a live remote host. Unless you already possess a password hash captured from the target system, Hashcat is incapable of performing the network-based brute-force attack described in the scenario.
- ✓
Hydra
Why this is correct
Hydra is a well-known network authentication cracker that performs online brute-force attacks by repeatedly submitting login credentials to a live service over the TCP/IP stack. For SSH specifically, Hydra invokes the SSH protocol handshake, supplies candidate username/password pairs, and inspects the server's authentication response to determine success. Its parallelism and modular protocol support (including the 'ssh' module) make it the appropriate choice for attacking a remote host where the password is guessed at the service itself.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is designed to process locally stored credential material—such as /etc/shadow entries, Kerberos tickets, or encrypted file formats—by comparing computed hash candidates against the captured digest. It has no protocol engine to establish a connection to an SSH daemon, negotiate encryption, or handle challenge-response exchanges across a network. Thus John is useless for an online brute-force attempt because it never contacts the remote service and instead relies on a pre-obtained hash file.
- ✗
Aircrack-ng
Why it's wrong here
Aircrack-ng is a suite focused exclusively on 802.11 wireless security: it captures frames such as IVs and handshakes, and cracks WEP keys or WPA/WPA2 passphrases from those offline frames. For an SSH brute force, there is no radio-frequency capture or handshake to crack; the target is a TCP-based application-layer service. Aircrack-ng cannot generate SSH authentication attempts, so selecting it reflects a misunderstanding of the target layer.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.