CEH Enumeration and System Hacking Practice Question
Which TWO of the following tools are used for password cracking?
⚠ Common exam trap
EC-CEH often tests the distinction between enumeration tools (e.g., Snmpwalk) and exploitation/cracking tools, so candidates may confuse SNMP enumeration with password cracking because SNMP community strings can be weak, but Snmpwalk itself does not crack passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat
Hashcat (B) is a correct answer because it is a dedicated, GPU-accelerated password recovery tool that cracks hashes for algorithms such as MD5, SHA-1, bcrypt, and NTLM using dictionary, brute-force, mask, and rule-based attacks. John the Ripper (C) is also correct because it is a classic password cracker that supports hundreds of hash and cipher formats, offers wordlist and incremental modes, and can auto-detect hash types. Wireshark (A) is a network protocol analyzer used for packet capture and traffic inspection, not for cracking passwords. Snmpwalk (D) is an SNMP enumeration utility that walks MIB trees to retrieve device information, and Nmap (E) is a port scanner and host-discovery tool with scripting support, neither of which is designed for password cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a powerful network protocol analyzer used for capturing and interactively browsing network traffic in real-time. While it can intercept unencrypted credentials or hashes transmitted over a network, it does not possess any inherent functionality to actively decrypt or crack these captured hashes into their plaintext passwords. Its primary role is passive observation, analysis, and debugging of network communications, not active cryptographic attack or password recovery.
- ✓
Hashcat
Why this is correct
Hashcat is a highly optimized, GPU-accelerated password recovery tool renowned for its speed and versatility in cracking various hash types, including MD5, SHA-1, NTLM, and numerous others. It supports a wide array of attack modes such as dictionary attacks, brute-force attacks, rule-based attacks, and hybrid attacks, leveraging the parallel processing power of modern graphics cards. This makes it exceptionally efficient for offline password cracking against captured hash dumps from compromised systems.
- ✓
John the Ripper
Why this is correct
John the Ripper, often abbreviated as JtR, is a widely used, open-source password cracking tool designed to detect weak passwords in Unix-like systems, although it supports numerous hash and cipher types across various operating systems. It employs dictionary attacks, brute-force attacks, and single crack modes to efficiently test password candidates against collected password hashes. JtR is particularly effective for auditing password strength and recovering lost passwords from compromised systems or databases.
- ✗
Snmpwalk
Why it's wrong here
Snmpwalk is a command-line utility used for querying network devices that support the Simple Network Management Protocol (SNMP) to retrieve information from their Management Information Bases (MIBs). Its primary function is network enumeration, allowing administrators and attackers to gather details about device configurations, interfaces, and system uptime. This process involves information gathering and reconnaissance, not the cryptographic computation required to crack passwords or authentication credentials.
- ✗
Nmap
Why it's wrong here
Nmap, or Network Mapper, is a free and open-source utility for network discovery and security auditing, primarily used for host discovery, port scanning, service version detection, and operating system fingerprinting. While Nmap can identify open ports and services that might be susceptible to password-related vulnerabilities (e.g., an open SSH port), it does not perform the actual password cracking process itself. Its role is reconnaissance and vulnerability identification, not brute-forcing or hash analysis.
Go deeper
Related to this question
Key term
SNMP Enumeration
SNMP Enumeration is the process of querying a device's Simple Network Management Protocol service to extract information about its configuration, running processes, user accounts, and network connections.
Key term
Password Cracking
Password cracking is the process of using software tools or techniques to recover unknown passwords from stored data or by guessing them systematically.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.