GCIH Attacking Passwords Practice Question
A penetration tester is attempting to crack NTLM hashes captured from a Windows environment. The hashes were obtained from a memory dump of a workstation. The tester decides to use Hashcat with the mode 1000. Which of the following best describes the type of hashes being cracked and the primary reason this mode is chosen?
⚠ Common exam trap
The trap here is assuming that mode 1000 handles NetNTLMv2 or Kerberos hashes, but each hash type has a distinct mode in Hashcat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTLM hashes, because mode 1000 is optimized for fast brute-force attacks against unsalted MD4-based hashes.
Hashcat mode 1000 is designated for NTLM hashes, which are MD4-based and unsalted. This makes them vulnerable to rapid brute-force and dictionary attacks. The other options misidentify the hash types and their corresponding Hashcat modes. Therefore, the correct answer is the one that correctly pairs NTLM with mode 1000 and explains the speed advantage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberos 5 TGS-REP hashes, because mode 1000 extracts service account credentials from ticket-granting tickets.
Why it's wrong here
Kerberos 5 TGS-REP hashes (from Kerberoasting) are cracked with mode 13100, not 1000. Mode 1000 does not handle Kerberos tickets. This option confuses different attack types and hash formats, making it incorrect for the scenario where NTLM hashes are being cracked.
- ✗
NetNTLMv2 hashes, because mode 1000 captures challenge-response pairs for network authentication.
Why it's wrong here
NetNTLMv2 hashes are used in network authentication and are cracked with modes like 5600, not 1000. Mode 1000 is for raw NTLM hashes from SAM or memory dumps. NetNTLMv2 involves a challenge-response mechanism and is not directly compatible with mode 1000, so this option is incorrect.
- ✗
LM hashes, because mode 1000 is designed to crack the older LAN Manager hash format.
Why it's wrong here
LM hashes are cracked with Hashcat mode 3000, not 1000. LM hashes are weaker and split passwords into two 7-character halves, but they are distinct from NTLM. Mode 1000 is specifically for NTLM, so this choice misidentifies the hash type and the corresponding mode.
- ✓
NTLM hashes, because mode 1000 is optimized for fast brute-force attacks against unsalted MD4-based hashes.
Why this is correct
Hashcat mode 1000 specifically targets NTLM hashes, which are unsalted MD4 hashes of the user's password. These are fast to compute, allowing high-speed brute-force and rule-based attacks. The lack of salting means identical passwords produce identical hashes, enabling precomputed attacks and efficient cracking, which is why this mode is chosen.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.