Courseiva
easyMultiple Choice

PT0-002 Practice Question: While performing a password audit, a tester finds…

While performing a password audit, a tester finds that the hash of 'Password123' is stored in the LAN Manager (LM) hash format. What is the primary security weakness of LM hashes?

⚠ Common exam trap

Watch out — candidates often confuse LM hashes with NTLM hashes, incorrectly associating the weakness with MD4 (which is used by NTLM) or salting, when the real vulnerability is the split into two 7-character halves that can be attacked independently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The password is split into two 7-character halves

The primary security weakness of LAN Manager (LM) hashes is that the password is converted to uppercase, padded or truncated to 14 characters, and then split into two 7-character halves. Each half is hashed independently using DES as the key for a known constant, which means an attacker can brute-force each 7-character half separately, drastically reducing the keyspace from 14 characters to two sets of 7 characters. This makes LM hashes extremely vulnerable to offline cracking, especially with modern tools like John the Ripper or Hashcat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The password is split into two 7-character halves

    Why this is correct

    The LM hash algorithm truncates the password to 14 characters and splits it into two 7-character halves. Each half is independently DES-encrypted with a constant key, so an attacker can brute-force each 7-character segment separately rather than attacking a 14-character password. This splitting reduces the effective keyspace from 95^14 to approximately 2 * 95^7, which is trivially small for modern offline cracking tools.

  • ✗

    The hash is case-sensitive

    Why it's wrong here

    LM hashes are case-insensitive because the password is uppercased before hashing. This means the effective alphabet for each character shrinks to 26 uppercase letters plus any digits and symbols that survive the uppercasing, substantially reducing the number of possible passwords an attacker must try. Claiming the hash is case-sensitive incorrectly suggests it retains case distinctions, when in fact it discards them and becomes easier to crack.

  • ✗

    The hash is salted with a weak random value

    Why it's wrong here

    LM hashes use no salt whatsoever. Salting is a mechanism to ensure identical passwords produce different hashes for different users, but LM hashes of the same password are always identical across accounts. A weak random salt would provide some protection against rainbow tables, but LM's unsalted design allows attackers to use precomputed lookup tables and instantly match common passwords.

  • ✗

    The hash uses the MD4 hashing algorithm

    Why it's wrong here

    LM hashes are computed using a legacy DES-based algorithm, not MD4. MD4 is the basis for NTLM hashes, which are a different and more robust mechanism used in modern Windows systems. The DES transformation in LM works on the split halves as described, making the hash vulnerable to brute-force and rainbow table attacks, whereas MD4-based NTLM at least retains case and does not split the password.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.