Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

You have captured an NTLMv2 hash from a LLMNR poisoning attack using Responder. Which tool and mode would you use to attempt to crack the hash using a dictionary attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat -m 5600 -a 0

Hashcat mode 5600 is for NTLMv2 hashes; -a 0 is dictionary attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hashcat -m 5600 -a 0

    Why this is correct

    Hashcat's -m 5600 specifically targets NetNTLMv2 hashes, the exact challenge-response format captured via LLMNR/NBNS poisoning tools like Responder. The -a 0 flag designates a straight dictionary attack, allowing you to feed a wordlist of candidate passwords. This is the correct and complete command for cracking the captured NTLMv2 hash, as it selects both the right hash type and the appropriate attack mode.

  • ✗

    John the Ripper --format=LM --wordlist

    Why it's wrong here

    John the Ripper's --format=LM expects a legacy LAN Manager hash, which uses a simple DES-based split of the password into two 7-character halves. An NTLMv2 hash is a challenge-response HMAC-MD5 construction, completely different in structure and computation. Even if you specify a wordlist, John will misparse the NTLMv2 formatted hash and fail to crack it; the proper John format would be --format=netntlmv2.

  • ✗

    Hashcat -m 1000 -a 0

    Why it's wrong here

    Hashcat -m 1000 is the mode for plain NTLM hashes, which are unsalted MD4 digests of the password Unicode string. NTLMv2 hashes are not a single hash of the password; they incorporate the server challenge and client nonce via HMAC-MD5, producing a longer and more complex value. Running -m 1000 against a captured NTLMv2 hash will yield no crack because the hash format is incompatible.

  • ✗

    John the Ripper --format=NT --wordlist

    Why it's wrong here

    John's --format=NT corresponds to the NT hash (also known as NTLM), the MD4-based hash stored in the SAM database, not the challenge-response NTLMv2 that LLMNR poisoning captures. Using this format will cause John to treat the NTLMv2 hash as an NT hash, leading to incorrect parsing or no results. The correct John format for NTLMv2 is --format=netntlmv2, which accounts for the challenge-response structure.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.