Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester wants to crack NTLM hashes captured from a Windows domain. Which hashcat mode should be used for NTLM hashes?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-m 1000

Hashcat mode 1000 corresponds to NTLM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    -m 1000

    Why this is correct

    Hashcat mode 1000 is the designated mode for cracking NT/NTLM hashes, the MD4-based hash of the UTF-16LE password used by Windows for authentication. When an attacker captures NTLM hashes (e.g., from the SAM database or NTDS.dit), mode 1000 is required because the hash format is not a generic MD5 or another algorithm; it's a specific Windows-specific format. This mode directly processes the raw 32-character hexadecimal NTLM hash and is the correct choice for this scenario.

  • ✗

    -m 13100

    Why it's wrong here

    Hashcat mode 13100 is intended for Kerberos 5 TGS-REP tickets, commonly used in Kerberoasting attacks against Active Directory service accounts. A TGS ticket contains a ciphertext that, when cracked offline, reveals the service account's password, but the hash format is entirely distinct from a Windows NTLM hash. Since the tester captured NTLM hashes, this mode would fail to parse the input and is therefore incorrect.

  • ✗

    -m 0

    Why it's wrong here

    Hashcat mode 0 corresponds to raw MD5, a generic message digest algorithm that produces a 128-bit hash used in many contexts such as legacy Unix passwords or simple file integrity. NTLM hashes, however, are based on MD4 (a different algorithm) and are stored in a specific hexadecimal representation that does not conform to MD5's format. Choosing mode 0 would attempt an MD5 attack against data that is not MD5, so it is the wrong choice for cracking Windows NTLM hashes.

  • ✗

    -m 22000

    Why it's wrong here

    Hashcat mode 22000 is used for WPA-PBKDF2-PMKID, which targets Wi-Fi Protected Access handshake captures, typically from wireless network reconnaissance. This mode processes the PMKID or EAPOL handshake from 802.11 frames, not any form of Windows authentication material. An NTLM hash is a plaintext-derived digest with a completely different structure; therefore using mode 22000 would be incorrect for this task.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.