easyMultiple Select
PT0-002 Practice Question: Which two tools are commonly used for password…
Which two tools are commonly used for password cracking in penetration testing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat
Hashcat (C) is a GPU-accelerated password recovery tool that supports hundreds of hash types (MD5, NTLM, bcrypt, WPA-PBKDF2, etc.) and attack modes like dictionary, brute-force, mask, and rule-based, making it a standard choice for cracking captured password hashes during penetration tests. John the Ripper (D) is another dedicated password cracker that auto-detects many hash formats, supports wordlist and incremental modes, and is widely used to crack /etc/shadow, NTLM, and other credential stores. The other options are not password-cracking tools: Metasploit (A) is an exploitation framework that may invoke crackers but is not itself one, Nmap (B) is a port scanner and service/OS fingerprinting tool, and Wireshark (E) is a packet capture and protocol analyzer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Metasploit
Why it's wrong here
Metasploit is an exploitation framework designed for developing, testing, and executing exploit code against vulnerable targets. It provides payloads, encoders, and post-exploitation modules to gain and maintain access, but it does not crack password hashes natively. While auxiliary modules can dump or retrieve hashes from compromised systems, Metasploit lacks the core attack algorithms and optimization needed for password recovery, so it is not categorized as a cracking tool.
- ✗
Nmap
Why it's wrong here
Nmap is a network mapping and security auditing utility that sends raw packets to discover hosts, services, open ports, and operating system details. Its core purpose is reconnaissance and service enumeration, not authentication bypass. While Nmap can run NSE scripts that interact with login services, it does not perform offline or online password cracking of hashes, making it inefficient and inappropriate for that dedicated task.
- ✓
Hashcat
Why this is correct
Hashcat is a high-speed password recovery tool that offloads attacks to GPUs, enabling extremely fast brute-force, dictionary, combinator, mask, and rule-based attacks. It supports hundreds of hash types, including NTLM, Kerberos 5, bcrypt, and md5crypt, making it a preferred choice for cracking hashes captured during penetration tests. Its performance and attack flexibility make it one of the de facto standards for offline password cracking.
- ✓
John the Ripper
Why this is correct
John the Ripper is a widely used offline password cracking tool that supports a broad range of hash algorithms, from traditional DES and MD5 to modern bcrypt and scrypt. It offers several attack modes—wordlist, mangling rules, incremental, and external scripting—and runs on CPUs across many platforms. Its portability and comprehensive built-in wordlist make it a reliable companion to Hashcat, especially in environments where GPU acceleration is unavailable.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and visually inspects data packets traversing a network in real time. It decrypts and dissects protocols to troubleshoot traffic, but it never attempts to recover passwords from hashes or perform brute-force attacks. In a limited sense, it can reveal plaintext credentials sent over insecure protocols, but that is passive sniffing, not active password cracking.
Go deeper
Related to this question
Learn chapter
RDP Exploitation and BlueKeep
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
John the Ripper
John the Ripper is a free and open-source password cracking tool used by security professionals to test password strength and by attackers to guess credentials.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.