CompTIA
PT0-003 · Question #230
During an assessment, a penetration tester obtains access to an internal server and would like to perform further reconnaissance by capturing LLMNR traffic. Which of the following tools should the tes
The correct answer is C. Responder. Responder is specifically designed to poison and capture LLMNR (and NetBIOS) name resolution traffic on the network, allowing the tester to collect authentication hashes for further attack.
Submitted by yousef_jo· Mar 6, 2026Post-exploitation and Lateral Movement
Question
During an assessment, a penetration tester obtains access to an internal server and would like to perform further reconnaissance by capturing LLMNR traffic. Which of the following tools should the tester use?
Options
- ABurp Suite
- BNetcat
- CResponder
- DNmap
How the community answered
(18 responses)- B6% (1)
- C94% (17)
Explanation
Responder is specifically designed to poison and capture LLMNR (and NetBIOS) name resolution traffic on the network, allowing the tester to collect authentication hashes for further attack.
Topics
#LLMNR poisoning#network reconnaissance#Responder#post-exploitation
Community Discussion
No community discussion yet for this question.