Courseiva

CEH Enumeration and System Hacking Practice Question

Which TWO of the following tools are used for password cracking?

⚠ Common exam trap

EC-CEH often tests the distinction between enumeration tools (e.g., Snmpwalk) and exploitation/cracking tools, so candidates may confuse SNMP enumeration with password cracking because SNMP community strings can be weak, but Snmpwalk itself does not crack passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat

Hashcat (B) is a correct answer because it is a dedicated, GPU-accelerated password recovery tool that cracks hashes for algorithms such as MD5, SHA-1, bcrypt, and NTLM using dictionary, brute-force, mask, and rule-based attacks. John the Ripper (C) is also correct because it is a classic password cracker that supports hundreds of hash and cipher formats, offers wordlist and incremental modes, and can auto-detect hash types. Wireshark (A) is a network protocol analyzer used for packet capture and traffic inspection, not for cracking passwords. Snmpwalk (D) is an SNMP enumeration utility that walks MIB trees to retrieve device information, and Nmap (E) is a port scanner and host-discovery tool with scripting support, neither of which is designed for password cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a powerful network protocol analyzer used for capturing and interactively browsing network traffic in real-time. While it can intercept unencrypted credentials or hashes transmitted over a network, it does not possess any inherent functionality to actively decrypt or crack these captured hashes into their plaintext passwords. Its primary role is passive observation, analysis, and debugging of network communications, not active cryptographic attack or password recovery.

  • ✓

    Hashcat

    Why this is correct

    Hashcat is a highly optimized, GPU-accelerated password recovery tool renowned for its speed and versatility in cracking various hash types, including MD5, SHA-1, NTLM, and numerous others. It supports a wide array of attack modes such as dictionary attacks, brute-force attacks, rule-based attacks, and hybrid attacks, leveraging the parallel processing power of modern graphics cards. This makes it exceptionally efficient for offline password cracking against captured hash dumps from compromised systems.

  • ✓

    John the Ripper

    Why this is correct

    John the Ripper, often abbreviated as JtR, is a widely used, open-source password cracking tool designed to detect weak passwords in Unix-like systems, although it supports numerous hash and cipher types across various operating systems. It employs dictionary attacks, brute-force attacks, and single crack modes to efficiently test password candidates against collected password hashes. JtR is particularly effective for auditing password strength and recovering lost passwords from compromised systems or databases.

  • ✗

    Snmpwalk

    Why it's wrong here

    Snmpwalk is a command-line utility used for querying network devices that support the Simple Network Management Protocol (SNMP) to retrieve information from their Management Information Bases (MIBs). Its primary function is network enumeration, allowing administrators and attackers to gather details about device configurations, interfaces, and system uptime. This process involves information gathering and reconnaissance, not the cryptographic computation required to crack passwords or authentication credentials.

  • ✗

    Nmap

    Why it's wrong here

    Nmap, or Network Mapper, is a free and open-source utility for network discovery and security auditing, primarily used for host discovery, port scanning, service version detection, and operating system fingerprinting. While Nmap can identify open ports and services that might be susceptible to password-related vulnerabilities (e.g., an open SSH port), it does not perform the actual password cracking process itself. Its role is reconnaissance and vulnerability identification, not brute-forcing or hash analysis.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.