GPEN Attacking Password Hashes Practice Question
During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?
⚠ Common exam trap
Candidates frequently confuse NTLMv1 and NTLMv2 modes in Hashcat, or attempt to use mode 1000 which is meant for the local SAM NT hash rather than network authentication captures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mode 5600, which targets NetNTLMv2 hashes captured during network authentication events or LLMNR/NBT-NS spoofing attacks.
Hashcat utilizes mode 5600 specifically for NetNTLMv2 hashes, which allows leveraging high-speed GPU acceleration to perform dictionary and mask attacks against captured enterprise authentication handshakes. Selecting the correct mode ensures hashcat parses the challenge, username, domain, and response fields accurately according to the standard NTLMv2 response format specification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mode 1000, which targets local Windows SAM NT hashes extracted from a compromised registry hive export.
Why it's wrong here
Mode 1000 cracks NT hashes from a SAM or registry export, which lack the server challenge needed to verify a captured network response. It is tempting because NT hashes are the fastest GPU target and the correct choice when you have extracted hashes locally rather than sniffed authentication traffic.
- ✗
Mode 5500, which is designed exclusively for cracking legacy NTLMv1 network authentication challenge-response pairs.
Why it's wrong here
Mode 5500 targets NTLMv1 challenge-response, whose weaker DES-based cryptography differs from the HMAC-MD5 construction in NTLMv2. It is tempting because NTLMv1 is genuinely crackable with mode 5500, and would be the correct choice when captured traffic uses legacy NTLMv1 rather than NTLMv2.
- ✓
Mode 5600, which targets NetNTLMv2 hashes captured during network authentication events or LLMNR/NBT-NS spoofing attacks.
Why this is correct
Mode 5600 targets the NetNTLMv2 challenge-response format, which is exactly what a captured NTLMv2 pair represents — not the stored NTLM hash (mode 1000). Hashcat reconstructs the HMAC-MD5 response using the captured server challenge, so GPU cracking proceeds efficiently against the network-captured pair.
- ✗
Mode 3000, which processes LanMan hashes historically found on very old Windows NT and 95 operating systems.
Why it's wrong here
Mode 3000 processes LanMan hashes, which are unsalted DES-derived values stored locally, not network challenge-response pairs. It is tempting because LanMan cracking is genuinely performed with mode 3000, and would be the correct choice when recovering passwords from legacy LM hashes in an old SAM database.
Visual reference
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.