Courseiva
Attacking Password Hashes →mediumMultiple Choice

GPEN Attacking Password Hashes Practice Question

During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?

⚠ Common exam trap

Candidates frequently confuse NTLM (mode 1000, representing the static password hash stored in the Active Directory database) with NetNTLMv2 (mode 5600, representing dynamic network authentication traffic), leading to failed offline attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mode 5600, targeting NetNTLMv2 network authentication captures.

Hashcat mode 5600 specifically targets NetNTLMv2 authentication exchanges captured during network sniffing or LLMNR/NBT-NS poisoning attacks. Using the correct mode ensures Hashcat formats the challenge, username, domain, and response fields properly for structural verification and decryption. Selecting incorrect modes results in immediate errors or zero matches during computation, making accurate identification of authentication protocols a vital pentesting skill.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mode 1000, targeting local SAM database NTLM hashes.

    Why it's wrong here

    Mode 1000 is strictly designated for cracking standalone NTLM password hashes extracted directly from the Windows SAM registry hive or Active Directory NTDS.dit database file. It cannot parse network-captured challenge-response pairs because those include server challenges and HMAC-MD5 calculation artifacts absent from static password hashes.

  • ✗

    Mode 1300, targeting legacy Windows NT hashes.

    Why it's wrong here

    Mode 1300 handles older MD4-based NT hashes combined with salt parameters or specific legacy formats from historical Windows versions. Network captures require protocol-specific parsers to separate the user response from the challenge nonce, rendering legacy NT hash modes completely incompatible with NetNTLMv2 traffic.

  • ✓

    Mode 5600, targeting NetNTLMv2 network authentication captures.

    Why this is correct

    Mode 5600 is engineered precisely for cracking NetNTLMv2 hashes gathered via protocol coercion or LLMNR poisoning. It correctly structures the username, domain, server challenge, client challenge, and response fields so Hashcat can execute the required HMAC-MD5 cryptographic validation loops during brute-forcing.

  • ✗

    Mode 3000, targeting LM hashes with challenge data.

    Why it's wrong here

    Mode 3000 relates to LanMan authentication mechanics and historical challenge-response systems used by vintage operating systems like Windows 95 and NT 4.0. Modern environments default to NTLMv2, making LanMan modes obsolete for capturing contemporary enterprise authentication exchanges during standard internal engagements.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.