PT0-002 Attacks and Exploits Practice Question
You have captured an NTLMv2 hash from a LLMNR poisoning attack using Responder. Which tool and mode would you use to attempt to crack the hash using a dictionary attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat -m 5600 -a 0
Hashcat mode 5600 is for NTLMv2 hashes; -a 0 is dictionary attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hashcat -m 5600 -a 0
Why this is correct
Hashcat's -m 5600 specifically targets NetNTLMv2 hashes, the exact challenge-response format captured via LLMNR/NBNS poisoning tools like Responder. The -a 0 flag designates a straight dictionary attack, allowing you to feed a wordlist of candidate passwords. This is the correct and complete command for cracking the captured NTLMv2 hash, as it selects both the right hash type and the appropriate attack mode.
- ✗
John the Ripper --format=LM --wordlist
Why it's wrong here
John the Ripper's --format=LM expects a legacy LAN Manager hash, which uses a simple DES-based split of the password into two 7-character halves. An NTLMv2 hash is a challenge-response HMAC-MD5 construction, completely different in structure and computation. Even if you specify a wordlist, John will misparse the NTLMv2 formatted hash and fail to crack it; the proper John format would be --format=netntlmv2.
- ✗
Hashcat -m 1000 -a 0
Why it's wrong here
Hashcat -m 1000 is the mode for plain NTLM hashes, which are unsalted MD4 digests of the password Unicode string. NTLMv2 hashes are not a single hash of the password; they incorporate the server challenge and client nonce via HMAC-MD5, producing a longer and more complex value. Running -m 1000 against a captured NTLMv2 hash will yield no crack because the hash format is incompatible.
- ✗
John the Ripper --format=NT --wordlist
Why it's wrong here
John's --format=NT corresponds to the NT hash (also known as NTLM), the MD4-based hash stored in the SAM database, not the challenge-response NTLMv2 that LLMNR poisoning captures. Using this format will cause John to treat the NTLMv2 hash as an NT hash, leading to incorrect parsing or no results. The correct John format for NTLMv2 is --format=netntlmv2, which accounts for the challenge-response structure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.