easyMultiple Choice
PT0-002 Practice Question: While performing a password audit, a tester finds…
While performing a password audit, a tester finds that the hash of 'Password123' is stored in the LAN Manager (LM) hash format. What is the primary security weakness of LM hashes?
⚠ Common exam trap
Watch out — candidates often confuse LM hashes with NTLM hashes, incorrectly associating the weakness with MD4 (which is used by NTLM) or salting, when the real vulnerability is the split into two 7-character halves that can be attacked independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The password is split into two 7-character halves
The primary security weakness of LAN Manager (LM) hashes is that the password is converted to uppercase, padded or truncated to 14 characters, and then split into two 7-character halves. Each half is hashed independently using DES as the key for a known constant, which means an attacker can brute-force each 7-character half separately, drastically reducing the keyspace from 14 characters to two sets of 7 characters. This makes LM hashes extremely vulnerable to offline cracking, especially with modern tools like John the Ripper or Hashcat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The password is split into two 7-character halves
Why this is correct
The LM hash algorithm truncates the password to 14 characters and splits it into two 7-character halves. Each half is independently DES-encrypted with a constant key, so an attacker can brute-force each 7-character segment separately rather than attacking a 14-character password. This splitting reduces the effective keyspace from 95^14 to approximately 2 * 95^7, which is trivially small for modern offline cracking tools.
- ✗
The hash is case-sensitive
Why it's wrong here
LM hashes are case-insensitive because the password is uppercased before hashing. This means the effective alphabet for each character shrinks to 26 uppercase letters plus any digits and symbols that survive the uppercasing, substantially reducing the number of possible passwords an attacker must try. Claiming the hash is case-sensitive incorrectly suggests it retains case distinctions, when in fact it discards them and becomes easier to crack.
- ✗
The hash is salted with a weak random value
Why it's wrong here
LM hashes use no salt whatsoever. Salting is a mechanism to ensure identical passwords produce different hashes for different users, but LM hashes of the same password are always identical across accounts. A weak random salt would provide some protection against rainbow tables, but LM's unsalted design allows attackers to use precomputed lookup tables and instantly match common passwords.
- ✗
The hash uses the MD4 hashing algorithm
Why it's wrong here
LM hashes are computed using a legacy DES-based algorithm, not MD4. MD4 is the basis for NTLM hashes, which are a different and more robust mechanism used in modern Windows systems. The DES transformation in LM works on the split halves as described, making the hash vulnerable to brute-force and rainbow table attacks, whereas MD4-based NTLM at least retains case and does not split the password.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Hydra for Credential Brute-Forcing
Key term
John the Ripper
John the Ripper is a free and open-source password cracking tool used by security professionals to test password strength and by attackers to guess credentials.
Key term
Hashcat
Hashcat is a powerful password recovery tool that uses various attack methods to crack password hashes, widely used by security professionals and penetration testers.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.