GPEN Password Attacks and Formats Practice Question
During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?
⚠ Common exam trap
A common mix-up: candidates confuse MS-CHAPv2 with NetNTLMv1 or assuming that general-purpose Wi-Fi cracking tools support PPP authentication protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat mode 5600 (MS-CHAPv2) with a wordlist.
MS-CHAPv2 challenge-response handshakes are cracked using Hashcat mode 5600 or John the Ripper's mschapv2 format. Hashcat mode 5600 correctly processes the challenge and response to recover the password. Other modes like 5500 are for different protocols (NetNTLMv1), and tools like Aircrack-ng are for Wi-Fi. Thus, the appropriate combination is Hashcat mode 5600 with a wordlist.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hashcat mode 5600 (MS-CHAPv2) with a wordlist.
Why this is correct
Hashcat mode 5600 is specifically designed for MS-CHAPv2 challenge-response pairs. It expects the format `username::::response:challenge`. This mode correctly implements the MS-CHAPv2 algorithm to derive the password from the captured handshake. Using a wordlist or rules with this mode is the standard approach for offline cracking of MS-CHAPv2. Thus, this is the correct tool and mode.
- ✗
Hashcat mode 5500 (NetNTLMv1) with a wordlist.
Why it's wrong here
Mode 5500 is for NetNTLMv1, not MS-CHAPv2. MS-CHAPv2 uses a different challenge-response format and requires mode 5600. Using mode 5500 would not correctly parse the captured handshake, leading to failure. NetNTLMv1 is used in different authentication scenarios, such as SMB relay. Therefore, this combination is incorrect for cracking MS-CHAPv2.
- ✗
Aircrack-ng with the `-E` option for MS-CHAPv2.
Why it's wrong here
Aircrack-ng is primarily for Wi-Fi (WEP/WPA) cracking and does not support MS-CHAPv2. The `-E` option in Aircrack-ng specifies the ESSID for WPA networks. MS-CHAPv2 is a PPP authentication protocol, not a Wi-Fi encryption protocol. Therefore, Aircrack-ng cannot crack MS-CHAPv2 handshakes; this option is invalid.
- ✗
John the Ripper with the `--format=netntlm` option.
Why it's wrong here
John the Ripper's `netntlm` format is for NetNTLM, not MS-CHAPv2. MS-CHAPv2 requires the `mschapv2` format in John. Using the wrong format will result in errors or no cracking. John does support MS-CHAPv2, but the specified format is incorrect. Therefore, this option is not appropriate for the given handshake.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.