GCIH Attacking Passwords Practice Question
An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the responder needs to prioritize cracking accounts with weak passwords using Hashcat. Which hash mode should be explicitly specified for cracking standard Windows NT LAN Manager (NTLM) password hashes extracted from this database?
⚠ Common exam trap
Candidates often confuse NTLM (mode 1000) with older LAN Manager hashes (mode 3000) or newer NetNTLMv2 challenge-response network authentication captures (mode 5600), leading to incorrect command execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mode 1000, which corresponds directly to standard NTLM password hashes.
Hashcat mode 1000 specifically targets NTLM password hashes, which are stored within the NTDS.dit database. Modern Windows environments heavily rely on NTLM for authentication fallback and pass-the-hash attacks, making these hashes critical targets for offline cracking during incident response engagements. Accurately identifying and utilizing the correct hash algorithm identifier ensures that computing resources are focused efficiently without wasting time on incompatible parsing formats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mode 3000, which is designated for legacy LAN Manager hashes.
Why it's wrong here
LAN Manager is an obsolete and cryptographically weak authentication protocol that has been disabled by default since Windows Vista and Windows Server 2008. While occasionally found in extremely legacy environments, NTDS.dit databases store modern NTLM hashes rather than original LM hashes.
- ✗
Mode 5600, which targets NetNTLMv2 network authentication captures.
Why it's wrong here
NetNTLMv2 hashes are captured over the network during authentication exchanges, such as through Responder or SMB relay attacks. They differ fundamentally in structure from the static password database hashes extracted directly from the NTDS.dit file.
- ✓
Mode 1000, which corresponds directly to standard NTLM password hashes.
Why this is correct
Hashcat utilizes mode 1000 specifically for NTLM hashes extracted from Windows operating system password databases. Providing this exact numerical identifier allows the cracking utility to properly parse the user account records and execute high-speed GPU-accelerated dictionary and rule-based attacks.
- ✗
Mode 13100, which is utilized for Kerberos 5 TGS-REP etype 23 tickets.
Why it's wrong here
Kerberos ticket hashes are targeted during Kerberoasting attacks where service tickets are requested from the domain controller. These hashes require an entirely different parsing mode and structure than the static account hashes stored natively within NTDS.dit.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.