PT0-002 Attacks and Exploits Practice Question
During a penetration test, you capture NTLM hashes by poisoning LLMNR requests. Which tool would you use to exploit this and obtain the hashes?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Responder
Responder is the primary tool used for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes from network authentication attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Responder
Why this is correct
Responder is a dedicated network-based attack tool that spoofs name resolution by sending malicious responses to LLMNR, NBT-NS, and mDNS queries. When a host tries to resolve a non-existent name, Responder answers and forces the client to authenticate to it, capturing NTLMv1/v2 challenge-response hashes in the process. These hashes are then offline-crackable or can be forwarded to ntlmrelayx for relay attacks, making Responder the standard tool for this initial hash-capture poisoning phase.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec (CME) is a Swiss-army knife for post-exploitation and lateral movement that operates on already-obtained credentials or hashes. It can validate credentials across SMB, SSH, WinRM, and execute commands, but it has no built-in protocol poisoning or network interception functionality to capture NTLM hashes from unauthenticated network traffic. As a result, it is not used for the initial LLMNR/NBT-NS poisoning stage but rather to leverage the hash or password once Responder has captured it.
- ✗
ntlmrelayx
Why it's wrong here
ntlmrelayx is an Impacket tool whose core purpose is to relay authenticated NTLM sessions to a target service, enabling attacks like SMB relay or LDAP-based attacks. While it can optionally save captured hashes to a file when run as a malicious server, it does not actively poison LLMNR/NBT-NS/mDNS name resolution; that poisoning function is done by Responder. Thus, ntlmrelayx consumes the hash/authentication relayed to it but is not the correct tool for the initial 'capture by poisoning' phase.
- ✗
Metasploit
Why it's wrong here
Metasploit's auxiliary modules (e.g., auxiliary/spoof/llmnr/llmnr_response) can theoretically spoof LLMNR, but this requires manual module selection, payload configuration, and does not provide the same turnkey, comprehensive poisoning and hash-capture workflow as Responder. Metasploit is primarily an exploitation framework focused on delivering payloads and post-exploitation actions, not a dedicated network protocol poisoning tool for NTLM hash capture. For a penetration test, using Responder is the standard, most efficient method for capturing NTLM hashes via LLMNR/NBT-NS/mDNS poisoning.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.