PEN-200 Password Attacks Practice Question
Exhibit
hashcat -m 1000 -a 0 hashes.txt rockyou.txt
Refer to the exhibit. What is the primary purpose of the command provided?
⚠ Common exam trap
Candidates frequently confuse Hashcat mode numbers, mistakenly applying modes meant for Kerberos or salted hashes when attempting to crack standard NTLM authentication hashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cracking NTLM hashes using a dictionary-based approach.
This command initiates a dictionary attack against NTLM hashes. Mode 1000 is specifically designated for NTLM authentication hashes, while -a 0 denotes a straight dictionary attack using a wordlist. Knowing how to map hash formats to their corresponding Hashcat mode is a fundamental skill for password cracking. Incorrectly identifying the mode or the attack type will result in an inability to recover the plaintext credentials during a penetration test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing a brute-force attack on a SHA-256 encrypted archive.
Why it's wrong here
The -m 1000 flag in Hashcat specifically targets NTLM authentication, not SHA-256 archives. SHA-256 archives would require different mode flags, such as 14100 for 7-zip. Consequently, this command would fail to produce meaningful results if applied to an archive file format as requested by the user.
- ✓
Cracking NTLM hashes using a dictionary-based approach.
Why this is correct
Mode 1000 identifies the hash type as NTLM, and -a 0 specifies the dictionary attack mode. This combination is the standard method for attempting to recover plaintext passwords from NTLM hashes using a predefined list of words, which is the most efficient starting point for offline password recovery in Windows environments.
- ✗
Attempting a mask attack to guess passwords based on a specific pattern.
Why it's wrong here
The -a 0 flag in Hashcat specifies a dictionary attack, which uses a list of words. A mask attack would require the -a 3 flag to define a character set and pattern. Therefore, the command does not perform a pattern-based guess, but rather iterates through the provided wordlist file.
- ✗
Extracting domain user hashes from a SAM database file.
Why it's wrong here
The command provided is for cracking already existing hashes contained within a file, not for extracting those hashes from a system database like the SAM file. Extraction requires tools like impacket-secretsdump or administrative access to the registry, which are distinct processes from the actual cracking phase performed by Hashcat.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.