Courseiva

GPEN Password Attacks and Formats Practice Question

During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?

⚠ Common exam trap

It's easy for candidates to confuse NetNTLMv2 with raw NTLM hashes or NetNTLMv1, leading to the use of an incorrect Hashcat mode that cannot parse the captured challenge-response pair.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mode 5600 (NetNTLMv2)

Responder captures NetNTLMv2 challenge-response pairs, which require Hashcat mode 5600 to crack. Mode 5600 correctly parses the username, domain, challenge, and response. Other modes like 5500 (NetNTLMv1), 1000 (NTLM), and 3000 (LM) are for different hash types and would not work. Selecting the correct mode is essential for successful offline cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mode 3000 (LM)

    Why it's wrong here

    Mode 3000 is for LM hashes, which are the outdated LAN Manager hashes. LM hashes are not used in NTLMv2 authentication and have a different format. Responder captures NTLMv2 challenges, not LM hashes. Using mode 3000 would not work and would waste time. It is important to match the mode to the captured hash type.

  • ✗

    Mode 5500 (NetNTLMv1)

    Why it's wrong here

    Mode 5500 is for NetNTLMv1, which is an older and weaker protocol. NTLMv1 uses DES-based encryption and is not the same as NTLMv2. Responder typically captures NTLMv2 by default in modern environments. Using mode 5500 on an NTLMv2 hash would result in parsing errors or no cracks, as the formats are incompatible.

  • ✗

    Mode 1000 (NTLM)

    Why it's wrong here

    Mode 1000 is for raw NTLM hashes, which are the unsalted MD4-based hashes stored in SAM or NTDS.dit. It does not handle challenge-response pairs. NTLMv2 captures include a server challenge and a response, which require a different cracking mode. Using mode 1000 on a captured NTLMv2 hash would fail because the hash format is different.

  • ✓

    Mode 5600 (NetNTLMv2)

    Why this is correct

    Hashcat mode 5600 is specifically designed for NetNTLMv2 challenge-response pairs, which are captured by tools like Responder. It correctly handles the format including the username, domain, server challenge, and HMAC-MD5 response. Using this mode allows efficient cracking of the captured hash. Other modes correspond to different hash types and would fail to parse the input correctly.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.