PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester captures NTLM hashes by spoofing LLMNR responses on the internal network. Which tool is most commonly used for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Responder
Responder is the standard tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ntlmrelayx
Why it's wrong here
ntlmrelayx is an impacket tool that consumes NTLM authentication messages captured elsewhere and forwards them to target services to authenticate as the victim. It does not poison protocols or sniff network traffic; it requires a valid hash or authentication attempt as input. Thus, while it can abuse NTLM hashes, it is not a capture mechanism and cannot be used to obtain them from network traffic.
- ✗
Hashcat
Why it's wrong here
Hashcat is a high-performance password recovery tool that cracks hashes by trying candidate passwords via brute force, dictionary, or rule-based attacks. It operates offline against already-obtained hash values, never on live network traffic. Therefore, it is incapable of capturing NTLM hashes; it only becomes relevant after an attacker has already harvested them.
- ✓
Responder
Why this is correct
Responder is a purpose-built tool for LLMNR, NBT-NS, and mDNS poisoning. It listens for broadcast name resolution requests and answers them, causing clients to send their NTLMv1/v2 authentication challenges to the attacker's machine. By doing so, it directly captures the NTLM hashes from the challenge-response handshake, making it the correct tool for this task.
- ✗
Bettercap
Why it's wrong here
Bettercap is a modular network attack framework focused on ARP spoofing, DNS spoofing, and SSL stripping for man-in-the-middle attacks. While it can perform credential sniffing via plugins and scripts, its primary mechanism does not target LLMNR/NBT-NS/mDNS poisoning out of the box. Capturing NTLM hashes via protocol poisoning is not its core purpose, unlike Responder which is specialized for that.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.