Certified Ethical Hacker (CEH) Practice Question

During a wireless penetration test you discover a WPA2-PSK access point, but there are no connected stations, so capturing the usual four-way handshake with airodump-ng is impractical. You decide to attempt the client-less PMKID attack instead. Which toolchain available on Kali Linux will both capture frames that contain the PMKID and convert the resulting capture into the hash format required by Hashcat's mode 22000?

  • Use airodump-ng with the --write option, then run airdecap-ng to pull out the PMKID.

  • Capture with hcxdumptool and convert the .pcapng using hcxpcapngtool to produce a mode 22000 hash.

  • Collect traffic in Kismet and export the log to cowpatty for PMKID extraction and cracking.

  • Record frames with tshark, generate a word list with crunch, and feed both directly into Hashcat.

Certified Ethical Hacker (CEH)
Wireless Network Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot