exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 156 discussion

Actual exam question from CompTIA's PT0-002
Question #: 156
Topic #: 1
[All PT0-002 Questions]

A penetration tester wants to test a list of common passwords against the SSH daemon on a network device. Which of the following tools would be BEST to use for this purpose?

  • A. Hashcat
  • B. Mimikatz
  • C. Patator
  • D. John the Ripper
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NotAHackerJustYet
Highly Voted 2 years, 3 months ago
Selected Answer: C
The correct answer is C. Patator. C. Patator is a multi-purpose tool for brute-forcing, particularly for testing a list of common passwords against an SSH daemon on a network device. It is designed to automate the process of attempting to log in using a variety of user-supplied passwords. This makes it the best tool for this purpose.
upvoted 6 times
NotAHackerJustYet
2 years, 3 months ago
A. Hashcat is a tool used for password cracking and recovery. It is designed to find weak passwords through brute-force attack. However, it is not the best tool for testing a list of common passwords against an SSH daemon on a network device, as it is not designed for this purpose. B. Mimikatz is a post-exploitation tool that can be used to gather credentials from various sources. It is not the best tool for testing a list of common passwords against an SSH daemon on a network device, as it is not designed for this purpose. D. John the Ripper is a password-cracking tool that can be used to crack passwords quickly and efficiently. It is not the best tool for testing a list of common passwords against an SSH daemon on a network device, as it is not designed for this purpose.
upvoted 2 times
...
...
Etc_Shadow28000
Most Recent 10 months, 2 weeks ago
Selected Answer: C
C. Patator Explanation: • Patator: Patator is a versatile brute-force tool that supports various protocols, including SSH. It allows testers to attempt multiple passwords against an SSH service efficiently and flexibly. Patator is specifically designed for scenarios like this, where you need to automate login attempts.
upvoted 1 times
...
solutionz
1 year, 9 months ago
Selected Answer: C
For the specific task of testing a list of common passwords against the SSH daemon on a network device, you would want to use a tool designed to perform brute-force attacks on network services like SSH. Among the options provided, the best tool for this task is: C. Patator Patator is a versatile brute-force tool that supports various network protocols, including SSH. It can be used to attempt to authenticate using a list of usernames and passwords, making it suitable for the task described.
upvoted 2 times
...
nickwen007
2 years, 2 months ago
Patator is a powerful brute-force tool that can be used to automate tests such as password guessing and authentication bypass. It can also be used to test the strength of passwords, perform dictionary attacks, and more.
upvoted 3 times
...
nickwen007
2 years, 2 months ago
The best answer is D. Deconfliction is necessary when the penetration test proceeds in parallel with a criminal digital forensic investigation.
upvoted 2 times
...
cy_analyst
2 years, 2 months ago
Selected Answer: C
Patator is a multi-purpose brute-forcer, which can be used for various tasks, such as testing passwords against various protocols and services, including SSH. It supports many protocols and services, including HTTP, FTP, SSH, Telnet, SMTP, and many more.
upvoted 4 times
[Removed]
2 years, 2 months ago
Yes C is correct
upvoted 2 times
...
...
beamage
2 years, 2 months ago
Selected Answer: C
The Books says Patator for SSH ftp,smb,vnc,zip
upvoted 4 times
...
kloug
2 years, 2 months ago
cccccccc
upvoted 3 times
...
BABrendan
2 years, 3 months ago
ChatGPT says C. He says that John the Ripper and Hashcat (while good..his words not mine) are not used for live attacks while Patator is.
upvoted 4 times
...
masso435
2 years, 5 months ago
I mean C not D.
upvoted 2 times
...
masso435
2 years, 5 months ago
Selected Answer: D
Hashcat and John the Ripper are both offline tools. Patator can be used for network attacks on services such as SSH.
upvoted 1 times
...
Treebeard88
2 years, 5 months ago
Selected Answer: A
From the Hashcat website - https://hashcat.net/wiki/ Core Attack Methods Dictionary attack - trying all words in a list; also called “straight” mode (attack mode 0, -a 0) Combinator attack - concatenating words from multiple wordlists (-a 1)
upvoted 2 times
...
mj944
2 years, 6 months ago
Selected Answer: C
https://www.kali.org/tools/patator/
upvoted 3 times
Treebeard88
2 years, 5 months ago
Patator is a brute force tool, does not utilize a wordlist of common passwords against a service or host - https://www.kali.org/tools/patator/#:~:text=Patator%20is%20a%20multi%2Dpurpose,telnet_login%20%3A%20Brute%2Dforce%20Telnet Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. Currently it supports the following modules: ftp_login : Brute-force FTP ssh_login : Brute-force SSH telnet_login : Brute-force Telnet There is no wordlist module on the kali tools page
upvoted 1 times
kmanb
2 years, 3 months ago
This is straight from my Kali machine: As you can see below you can pass in a wordlist file in the password parameter for the ssh_login module. kali@kali:~$ patator ssh_login --help Patator 0.9 (https://github.com/lanjelot/patator) with python-3.9.2 Usage: ssh_login <module-options ...> [global-options ...] Examples: ssh_login host=10.0.0.1 user=root password=FILE0 0=passwords.txt -x ignore:mesg='Authentication failed.'
upvoted 3 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago