Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester captures NTLM hashes by spoofing LLMNR responses on the internal network. Which tool is most commonly used for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Responder

Responder is the standard tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ntlmrelayx

    Why it's wrong here

    ntlmrelayx is an impacket tool that consumes NTLM authentication messages captured elsewhere and forwards them to target services to authenticate as the victim. It does not poison protocols or sniff network traffic; it requires a valid hash or authentication attempt as input. Thus, while it can abuse NTLM hashes, it is not a capture mechanism and cannot be used to obtain them from network traffic.

  • ✗

    Hashcat

    Why it's wrong here

    Hashcat is a high-performance password recovery tool that cracks hashes by trying candidate passwords via brute force, dictionary, or rule-based attacks. It operates offline against already-obtained hash values, never on live network traffic. Therefore, it is incapable of capturing NTLM hashes; it only becomes relevant after an attacker has already harvested them.

  • ✓

    Responder

    Why this is correct

    Responder is a purpose-built tool for LLMNR, NBT-NS, and mDNS poisoning. It listens for broadcast name resolution requests and answers them, causing clients to send their NTLMv1/v2 authentication challenges to the attacker's machine. By doing so, it directly captures the NTLM hashes from the challenge-response handshake, making it the correct tool for this task.

  • ✗

    Bettercap

    Why it's wrong here

    Bettercap is a modular network attack framework focused on ARP spoofing, DNS spoofing, and SSL stripping for man-in-the-middle attacks. While it can perform credential sniffing via plugins and scripts, its primary mechanism does not target LLMNR/NBT-NS/mDNS poisoning out of the box. Capturing NTLM hashes via protocol poisoning is not its core purpose, unlike Responder which is specialized for that.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.