Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hydra

Hydra is a fast online brute-force tool that supports many protocols including SSH.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hashcat

    Why it's wrong here

    Hashcat is a pure offline password recovery tool: it cracks raw dumped password hashes (e.g., NTLM, bcrypt, SHA-512) using CPU/GPU vectorization. It cannot send TCP SYN packets, open an SSH session, or iterate through username/password pairs against a live remote host. Unless you already possess a password hash captured from the target system, Hashcat is incapable of performing the network-based brute-force attack described in the scenario.

  • ✓

    Hydra

    Why this is correct

    Hydra is a well-known network authentication cracker that performs online brute-force attacks by repeatedly submitting login credentials to a live service over the TCP/IP stack. For SSH specifically, Hydra invokes the SSH protocol handshake, supplies candidate username/password pairs, and inspects the server's authentication response to determine success. Its parallelism and modular protocol support (including the 'ssh' module) make it the appropriate choice for attacking a remote host where the password is guessed at the service itself.

  • ✗

    John the Ripper

    Why it's wrong here

    John the Ripper is designed to process locally stored credential material—such as /etc/shadow entries, Kerberos tickets, or encrypted file formats—by comparing computed hash candidates against the captured digest. It has no protocol engine to establish a connection to an SSH daemon, negotiate encryption, or handle challenge-response exchanges across a network. Thus John is useless for an online brute-force attempt because it never contacts the remote service and instead relies on a pre-obtained hash file.

  • ✗

    Aircrack-ng

    Why it's wrong here

    Aircrack-ng is a suite focused exclusively on 802.11 wireless security: it captures frames such as IVs and handshakes, and cracks WEP keys or WPA/WPA2 passphrases from those offline frames. For an SSH brute force, there is no radio-frequency capture or handshake to crack; the target is a TCP-based application-layer service. Aircrack-ng cannot generate SSH authentication attempts, so selecting it reflects a misunderstanding of the target layer.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.