GPEN Attacking Password Hashes Practice Question
During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?
⚠ Common exam trap
Candidates frequently confuse NTLM (mode 1000, representing the static password hash stored in the Active Directory database) with NetNTLMv2 (mode 5600, representing dynamic network authentication traffic), leading to failed offline attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mode 5600, targeting NetNTLMv2 network authentication captures.
Hashcat mode 5600 specifically targets NetNTLMv2 authentication exchanges captured during network sniffing or LLMNR/NBT-NS poisoning attacks. Using the correct mode ensures Hashcat formats the challenge, username, domain, and response fields properly for structural verification and decryption. Selecting incorrect modes results in immediate errors or zero matches during computation, making accurate identification of authentication protocols a vital pentesting skill.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mode 1000, targeting local SAM database NTLM hashes.
Why it's wrong here
Mode 1000 is strictly designated for cracking standalone NTLM password hashes extracted directly from the Windows SAM registry hive or Active Directory NTDS.dit database file. It cannot parse network-captured challenge-response pairs because those include server challenges and HMAC-MD5 calculation artifacts absent from static password hashes.
- ✗
Mode 1300, targeting legacy Windows NT hashes.
Why it's wrong here
Mode 1300 handles older MD4-based NT hashes combined with salt parameters or specific legacy formats from historical Windows versions. Network captures require protocol-specific parsers to separate the user response from the challenge nonce, rendering legacy NT hash modes completely incompatible with NetNTLMv2 traffic.
- ✓
Mode 5600, targeting NetNTLMv2 network authentication captures.
Why this is correct
Mode 5600 is engineered precisely for cracking NetNTLMv2 hashes gathered via protocol coercion or LLMNR poisoning. It correctly structures the username, domain, server challenge, client challenge, and response fields so Hashcat can execute the required HMAC-MD5 cryptographic validation loops during brute-forcing.
- ✗
Mode 3000, targeting LM hashes with challenge data.
Why it's wrong here
Mode 3000 relates to LanMan authentication mechanics and historical challenge-response systems used by vintage operating systems like Windows 95 and NT 4.0. Modern environments default to NTLMv2, making LanMan modes obsolete for capturing contemporary enterprise authentication exchanges during standard internal engagements.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.