Courseiva

GPEN Attacking Password Hashes Practice Question

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

⚠ Common exam trap

The trap here is thinking that NTLMv2 hashes can be cracked with rainbow tables, but the inclusion of a unique server challenge per session prevents precomputation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat mode 5600 is used for NTLMv2 hashes.

NTLMv2 challenge-response pairs are cracked using Hashcat mode 5600, and the captured hash must include the server challenge for the computation to be possible. The challenge is unique per authentication, so precomputed tables are useless. The username is part of the hash but does not act as a salt. An attack mode must always be specified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NTLMv2 hashes can be cracked using precomputed rainbow tables.

    Why it's wrong here

    Rainbow tables are ineffective against NTLMv2 because each hash incorporates a unique server challenge and client nonce, making precomputation impractical. The challenge-response mechanism ensures that the same password produces different hashes for each authentication attempt. Therefore, rainbow tables cannot be used; instead, brute-force or dictionary attacks with the specific challenge are required.

  • ✓

    Hashcat mode 5600 is used for NTLMv2 hashes.

    Why this is correct

    Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are the challenge-response pairs captured from network traffic. This mode correctly handles the format of NTLMv2 responses, including the server challenge and the HMAC-MD5 construction. Using the correct mode ensures that Hashcat can perform the necessary computations to test candidate passwords against the captured challenge-response.

  • ✓

    Cracking NTLMv2 requires the original server challenge to be included in the hash file.

    Why this is correct

    NTLMv2 responses are computed using the server challenge, so the captured hash file must include this challenge for Hashcat to correctly test candidate passwords. Without the challenge, the computation cannot be replicated, and cracking would fail. Hashcat mode 5600 expects the challenge to be part of the input line, typically formatted as user::domain:challenge:response:blob.

  • ✗

    Hashcat can crack NTLMv2 hashes without specifying a wordlist or mask.

    Why it's wrong here

    Hashcat requires an attack mode, such as a wordlist, mask, or combinator attack, to generate candidate passwords. It does not have a built-in default wordlist or the ability to magically crack hashes without input. The tester must provide a wordlist, rules, or mask to attempt cracking. Without specifying an attack method, Hashcat will not proceed.

  • ✗

    NTLMv2 hashes are salted with the username, making them more resistant to cracking.

    Why it's wrong here

    While the username is included in the NTLMv2 hash computation, it is not a salt in the traditional sense. The primary resistance comes from the server challenge and client nonce, which are unique per authentication. The username is known and does not add significant computational difficulty. Therefore, stating that it is salted with the username is misleading and not the main factor.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.