Courseiva
easyMultiple Choice

PT0-002 Practice Question: During a penetration test, a tester needs to…

During a penetration test, a tester needs to perform a man-in-the-middle attack on a network that uses WPA2-Enterprise with PEAP. Which tool is most appropriate for capturing the authentication handshake to attempt offline cracking?

⚠ Common exam trap

Many candidates confuse aircrack-ng's ability to capture WPA2-PSK handshakes with the different requirements of WPA2-Enterprise, where the attack targets the MSCHAPv2 credentials rather than the 4-way handshake.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hostapd-wpe

hostapd-wpe (Wireless Pwnage Edition) is specifically designed to set up a rogue access point that impersonates a legitimate WPA2-Enterprise network. It captures the MSCHAPv2 challenge-response from the PEAP authentication handshake, which can then be used for offline dictionary or brute-force attacks against the user's credentials. Unlike other tools, hostapd-wpe handles the full EAP/PEAP exchange required for this attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a passive packet sniffer and protocol analyzer. While it can capture the 802.11 frames and EAPOL messages exchanged during a WPA2-Enterprise connection, it lacks the ability to actively inject frames, impersonate an access point, or operate a rogue RADIUS server. A penetration tester needs to perform an active MITM attack to observe and harvest the full EAP-PEAP authentication exchange, not merely eavesdrop on traffic that may not include a complete handshake without active manipulation.

  • ✗

    aircrack-ng

    Why it's wrong here

    aircrack-ng is a suite focused on cracking WEP and WPA/WPA2-PSK. It works by capturing the 4-way handshake and then performing dictionary or brute-force attacks against the derived Pairwise Master Key (PMK), which is computed from a pre-shared passphrase. In WPA2-Enterprise with PEAP, authentication uses per-user credentials validated by a RADIUS server, and there is no shared PSK; therefore, aircrack-ng cannot crack the EAP-based credentials or capture the MSCHAPv2 challenge-response that hostapd-wpe targets.

  • ✗

    Ettercap

    Why it's wrong here

    Ettercap is a comprehensive tool for conducting LAN-level MITM attacks, including ARP spoofing, DNS spoofing, and session hijacking. However, it is designed for wired Ethernet networks and operates at Layer 2/3 by redirecting traffic between hosts through its own interface. It does not implement the wireless 802.11 radio interface, rogue AP functionality, or a fake 802.1X/RADIUS server, so it cannot intercept EAP-PEAP authentication frames required to harvest enterprise credentials.

  • ✓

    hostapd-wpe

    Why this is correct

    hostapd-wpe is the correct tool because it turns a standard wireless card into a rogue access point that poses as a legitimate corporate AP. It embeds a modified RADIUS server that accepts EAP-PEAP sessions and captures the MSCHAPv2 challenge and response messages exchanged with the client. These captured hashes can then be cracked offline using tools like asleap or hashcat, making it the standard utility for attacking WPA2-Enterprise PEAP configurations during penetration tests.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.