PEN-200 Password Attacks Practice Question
During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?
⚠ Common exam trap
The trap here is selecting the wrong Hashcat mode (e.g., 1000 for NTLM) or assuming that relaying the hash recovers the password.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat with mode 5600 and a wordlist combined with rule-based mutations.
NetNTLMv2 hashes are challenge-response pairs that cannot be used directly for pass-the-hash. To recover the plaintext, offline cracking is required. Hashcat mode 5600 is designed for NetNTLMv2, and combining a wordlist with rules significantly improves success rates by mimicking common password transformations. Other modes or tools may work but are less efficient or incorrect for this hash type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat with mode 1000 and a mask attack targeting eight-character passwords.
Why it's wrong here
Hashcat mode 1000 is for NTLM (the raw hash), not NetNTLMv2. Using the wrong mode will result in failure to crack because the hash format is incompatible. A mask attack targeting eight characters is also inefficient for NetNTLMv2, which requires a challenge and response. The correct mode is 5600, and a wordlist with rules is more effective than a blanket mask attack for typical password policies.
- ✗
John the Ripper with `--format=netntlmv2` and the `--incremental` mode.
Why it's wrong here
John the Ripper does support NetNTLMv2 via the `netntlmv2` format, but the `--incremental` mode performs a brute-force attack that is extremely slow and unlikely to succeed for complex passwords. For efficiency, a wordlist with rules is preferred. Additionally, Hashcat is generally faster for this hash type due to better GPU optimization. While John can crack NetNTLMv2, it is not the most efficient choice in this scenario.
- ✗
Use `responder` to relay the hash to another host and gain access without cracking.
Why it's wrong here
Responder is used to capture NetNTLMv2 hashes, not to crack them. Relaying the hash to another host (SMB relay) can yield access without cracking, but the scenario asks specifically to crack the hash offline to recover the plaintext password. Relaying does not recover the password; it only allows authentication to a different service if the conditions are right. Therefore, this does not meet the requirement of offline cracking.
- ✓
Hashcat with mode 5600 and a wordlist combined with rule-based mutations.
Why this is correct
Hashcat mode 5600 is specifically for NetNTLMv2 hashes. Using a wordlist with rule-based mutations (e.g., best64.rule) increases the likelihood of cracking common password patterns. This approach is efficient because it leverages GPU acceleration and targets the exact hash format. The challenge-response nature of NetNTLMv2 means the hash cannot be used directly for pass-the-hash, so cracking is often necessary to obtain the plaintext for further access.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.