Courseiva

GPEN Advanced Password Attacks Practice Question

A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?

⚠ Common exam trap

Test-takers frequently confuse NTLM with NetNTLMv1 or NetNTLMv2, leading to selection of the wrong Hashcat mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat mode 1000

NTLM hashes are MD4-based and are cracked using Hashcat mode 1000. This mode correctly interprets the hash format and applies the appropriate algorithm. Other modes target different hash types such as NetNTLMv1, NetNTLMv2, or LM, and will not work for NTLM hashes. Therefore, mode 1000 is the only correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hashcat mode 3000

    Why it's wrong here

    Mode 3000 is for LM hashes, an older and weaker hash format. LM hashes are not the same as NTLM hashes and have a different structure and length. Using mode 3000 for NTLM hashes will not yield correct results because the algorithms differ. The tester must select the mode that matches the hash type to ensure successful cracking.

  • ✗

    Hashcat mode 5500

    Why it's wrong here

    Mode 5500 is for NetNTLMv1 hashes, which are challenge-response hashes used in network authentication. NTLM hashes are different; they are the raw MD4 hashes of passwords stored locally. Using mode 5500 on NTLM hashes will not work because the hash formats and algorithms are incompatible. The tester would not be able to crack the hashes correctly with this mode.

  • ✗

    Hashcat mode 5600

    Why it's wrong here

    Mode 5600 is for NetNTLMv2 hashes, which involve a challenge-response mechanism. NTLM hashes are not challenge-response; they are simple MD4 hashes. Therefore, mode 5600 is incorrect for cracking NTLM hashes. Attempting to use it would result in parsing errors or failure to crack, as the hash structure does not match the mode's requirements.

  • ✓

    Hashcat mode 1000

    Why this is correct

    Hashcat mode 1000 is specifically for NTLM hashes. NTLM hashes are MD4-based and are commonly found in Windows environments. Using mode 1000 allows Hashcat to correctly parse and crack these hashes. This is the standard mode for NTLM and is widely used in penetration testing when dealing with Windows password hashes extracted from SAM or NTDS.dit files.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.