Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During an internal penetration test, a tester wants to capture NTLMv2 hashes by poisoning LLMNR and NBT-NS traffic. Which tool should the tester use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Responder

Responder is specifically designed to respond to LLMNR and NBT-NS queries and capture NetNTLM hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ntlmrelayx

    Why it's wrong here

    ntlmrelayx is a tool for relaying captured NTLM authentication attempts to other services, often used after poisoning has occurred, but it does not itself listen for LLMNR/NBT-NS queries or spoof responses. It requires already captured hashes or authentication requests, so it cannot satisfy the stem's requirement to poison those protocols. Instead, it is a post-exploitation or relay tool that leverages credentials obtained via other means.

  • ✗

    Bettercap

    Why it's wrong here

    Bettercap is a comprehensive network attack framework that primarily performs ARP spoofing, DNS hijacking, and HTTP/HTTPS interception at the data-link and network layers. While it can perform some name resolution poisoning in certain modules, its core functionality is not focused on LLMNR/NBT-NS spoofing; it targets layer 2/3 traffic redirection rather than the Windows-specific name resolution protocols described in the stem. Thus, it would not directly capture NTLMv2 hashes via LLMNR/NBT-NS poisoning.

  • ✗

    Hashcat

    Why it's wrong here

    Hashcat is a password recovery tool that uses GPU-accelerated brute-force, dictionary, and rule-based attacks to crack password hashes locally. It has no ability to listen on a network, send spoofed responses, or intercept authentication challenges; it operates purely on pre-acquired hash values. Therefore, it cannot be used to capture or poison LLMNR/NBT-NS traffic, and is only relevant after a hash has already been obtained by a tool like Responder.

  • ✓

    Responder

    Why this is correct

    Responder operates by listening for Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) queries, then spoofing responses to redirect authentication attempts to the attacker’s machine, thereby capturing NTLMv2 challenge-response hashes. This directly satisfies the stem’s requirement to poison those specific protocols during an internal test, unlike tools that target different layers or authentication mechanisms.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.