PT0-002 Vulnerability Discovery and Analysis Practice Question
During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aireplay-ng
Airodump-ng captures the handshake, and aireplay-ng sends deauth packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
airmon-ng
Why it's wrong here
Airmon-ng enables monitor mode on a wireless interface, which is a prerequisite for packet injection and capture, but it does not itself send deauthentication frames or capture a WPA handshake. It is tempting because it is the first tool used in any Aircrack-ng workflow to prepare the interface, and in a scenario where the tester only needed to enable monitor mode before running another tool, it would be the correct choice.
- ✗
aircrack-ng
Why it's wrong here
aircrack-ng is a post-capture utility that takes a captured WPA/WPA2 4-way handshake and runs offline dictionary or brute-force attacks against the PSK. It does not inject deauthentication frames or capture network traffic, so it is only used after aireplay-ng and airodump-ng have completed their roles in the live attack.
- ✓
aireplay-ng
Why this is correct
aireplay-ng is the correct tool because it can inject arbitrary 802.11 frames, including deauthentication packets. The command `aireplay-ng -0 <count> -a <BSSID> <interface>` sends repeated deauth frames to disconnect connected clients, forcing them to reconnect and generate new EAPOL handshakes that airodump-ng can capture. It is the active component of the deauthentication attack.
- ✓
airodump-ng
Why this is correct
airodump-ng is the wireless capture utility that passively monitors 802.11 channels and records raw frames, including the 4-way EAPOL handshake exchanges that occur when a client reconnects. It cannot send deauthentication frames or other injected traffic; its role is to listen and log handshake data for subsequent cracking by aircrack-ng.
- ✗
airolib-ng
Why it's wrong here
airolib-ng is a management tool for building and maintaining ESSID and password databases used to speed up WPA/WPA2 PSK cracking via precomputed hash tables. It has no capability to inject deauth frames or capture network traffic, so it is irrelevant to the live wireless attack phase and would only be used during offline cracking preparation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.