Courseiva

GPEN Attacking Password Hashes Practice Question

A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?

⚠ Common exam trap

Watch out — candidates often confuse raw NT hashes (mode 1000) with network-captured NTLMv2 challenge-response pairs (mode 5600), as both relate to NTLM but require different cracking approaches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat mode 5600 (NetNTLMv2)

Hashcat mode 5600 is the correct choice because it is tailored for NetNTLMv2 challenge-response pairs, which are commonly captured during penetration tests. This mode understands the structure of the NTLMv2 response, including the server challenge and the HMAC-MD5 computation. Other modes target different hash types, such as raw NT hashes or Kerberos tickets, and would not correctly parse or crack the captured NTLMv2 data. Using the right mode ensures efficient and successful cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hashcat mode 0 (MD5)

    Why it's wrong here

    Hashcat mode 0 is used for raw MD5 hashes, which are unrelated to NTLMv2 challenge-response pairs. NTLMv2 responses are not simple MD5 hashes; they involve HMAC-MD5 computations over a challenge and other data. Using mode 0 would fail because the hash format does not match, and Hashcat would not parse the captured pair correctly. The scenario requires a mode specifically designed for NTLMv2 network captures.

  • ✓

    Hashcat mode 5600 (NetNTLMv2)

    Why this is correct

    Hashcat mode 5600 is specifically designed for NetNTLMv2 (also called NTLMv2) challenge-response pairs captured from network traffic. It correctly parses the username, domain, server challenge, and response fields to perform an offline dictionary or brute-force attack. This is the correct mode because the scenario involves a captured challenge-response pair, not a raw NT hash. Using the wrong mode would result in errors or no cracks.

  • ✗

    Hashcat mode 13100 (Kerberos 5 TGS-REP)

    Why it's wrong here

    Hashcat mode 13100 is used for Kerberos 5 TGS-REP etype 23 hashes, which are obtained from Kerberoasting attacks. These hashes are fundamentally different from NTLMv2 challenge-response pairs; they involve Kerberos ticket encryption rather than NTLM authentication. While both are network-captured credentials, the formats and cracking methods differ. The scenario specifies NTLMv2, so a Kerberos-specific mode would not work.

  • ✗

    Hashcat mode 1000 (NTLM)

    Why it's wrong here

    Hashcat mode 1000 is for cracking raw NT hashes (the unsalted MD4 of the password), not NTLMv2 challenge-response pairs. A raw NT hash is a 32-character hexadecimal string, while an NTLMv2 response includes a username, domain, challenge, and two response fields. Mode 1000 would not correctly process the captured network authentication data. The tester needs a mode that handles the challenge-response structure of NTLMv2.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.