GPEN Attacking Password Hashes Practice Question
A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)
⚠ Common exam trap
The trap here is thinking that NTLMv2 hashes can be cracked with rainbow tables, but the inclusion of a unique server challenge per session prevents precomputation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat mode 5600 is used for NTLMv2 hashes.
NTLMv2 challenge-response pairs are cracked using Hashcat mode 5600, and the captured hash must include the server challenge for the computation to be possible. The challenge is unique per authentication, so precomputed tables are useless. The username is part of the hash but does not act as a salt. An attack mode must always be specified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NTLMv2 hashes can be cracked using precomputed rainbow tables.
Why it's wrong here
Rainbow tables are ineffective against NTLMv2 because each hash incorporates a unique server challenge and client nonce, making precomputation impractical. The challenge-response mechanism ensures that the same password produces different hashes for each authentication attempt. Therefore, rainbow tables cannot be used; instead, brute-force or dictionary attacks with the specific challenge are required.
- ✓
Hashcat mode 5600 is used for NTLMv2 hashes.
Why this is correct
Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are the challenge-response pairs captured from network traffic. This mode correctly handles the format of NTLMv2 responses, including the server challenge and the HMAC-MD5 construction. Using the correct mode ensures that Hashcat can perform the necessary computations to test candidate passwords against the captured challenge-response.
- ✓
Cracking NTLMv2 requires the original server challenge to be included in the hash file.
Why this is correct
NTLMv2 responses are computed using the server challenge, so the captured hash file must include this challenge for Hashcat to correctly test candidate passwords. Without the challenge, the computation cannot be replicated, and cracking would fail. Hashcat mode 5600 expects the challenge to be part of the input line, typically formatted as user::domain:challenge:response:blob.
- ✗
Hashcat can crack NTLMv2 hashes without specifying a wordlist or mask.
Why it's wrong here
Hashcat requires an attack mode, such as a wordlist, mask, or combinator attack, to generate candidate passwords. It does not have a built-in default wordlist or the ability to magically crack hashes without input. The tester must provide a wordlist, rules, or mask to attempt cracking. Without specifying an attack method, Hashcat will not proceed.
- ✗
NTLMv2 hashes are salted with the username, making them more resistant to cracking.
Why it's wrong here
While the username is included in the NTLMv2 hash computation, it is not a salt in the traditional sense. The primary resistance comes from the server challenge and client nonce, which are unique per authentication. The username is known and does not add significant computational difficulty. Therefore, stating that it is salted with the username is misleading and not the main factor.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.