20+ practice questions focused on Attacking Passwords — one of the most tested topics on the GIAC Certified Incident Handler exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Attacking Passwords PracticeAn incident responder identifies a compromised workstation using a hash-based NTLM relay attack. Which specific protocol vulnerability is being exploited by the attacker to intercept and pass authentication tokens to a target server without cracking the password?
Explanation: NTLM relay attacks exploit the lack of mutual authentication in NTLM, allowing an attacker to intercept authentication requests and forward them to a target service. This is a critical vector in internal network pivoting because it bypasses the need for plaintext credentials. Organizations must deploy SMB signing or Kerberos-only authentication to mitigate these vulnerabilities, as NTLM does not inherently verify the identity of the server receiving the request.
An organization is auditing its password policies and hash storage. Which TWO of the following practices are considered industry-standard defenses against rapid offline dictionary attacks on hashed credentials?
Explanation: Salting and computationally expensive hashing functions are the primary defenses against offline attacks. By adding unique salt values, attackers cannot use precomputed rainbow tables effectively, forcing them to crack each password individually. Using slow algorithms like Argon2 or bcrypt increases the time required for every guess, making large-scale brute-force attempts computationally prohibitive for attackers. These controls are foundational for protecting user credentials against database exfiltration incidents.
During an engagement, you observe an attacker attempting to perform a 'Pass-the-Hash' attack. Which THREE of the following conditions or configurations are necessary for the attacker to successfully execute this technique?
Explanation: Pass-the-Hash requires the attacker to have already obtained the NTLM hash of a user. The target system must support NTLM authentication, and the attacker must have the ability to transmit this hash to the authentication service. It does not require cracking the hash, but it does require the target to accept the hash as valid authentication material, often facilitated by a lack of Kerberos-only enforcement or legacy protocol support.
An incident responder is analyzing a memory dump from a Windows domain controller and discovers cleartext credentials cached in LSASS.memory. Which utility native to modern Windows operating systems is most commonly abused by attackers to dump this process memory without triggering basic file-activity alerts on disk?
Explanation: Tasklist or Taskmgr are visible, but Task Manager requires GUI interaction and writes process data differently. ProcDump is a legitimate Microsoft Sysinternals tool that creates mini-dumps of processes, making it a favorite for living-off-the-land attacks against LSASS. Understanding this helps incident handlers identify legitimate administrative tools repurposed by malicious actors to bypass standard endpoint monitoring.
An incident responder is examining a Windows 10 workstation that was compromised via a phishing email. The attacker gained initial access and then extracted cached domain credentials from the system. The responder finds evidence that the attacker used the 'reg save' command to export registry hives and later extracted password hashes offline. Which of the following registry hives would contain the local SAM database and cached domain logons that the attacker likely targeted?
Explanation: The SAM hive holds local account hashes, while the SECURITY hive holds cached domain credentials used for offline logon. An attacker who exports both with 'reg save' can later extract these hashes offline using tools like secretsdump. The SYSTEM hive is required for decryption but does not itself contain the cached domain logons, making the combination of SAM and SECURITY the correct target.
+15 more Attacking Passwords questions available
Practice all Attacking Passwords questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Attacking Passwords. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Attacking Passwords questions on the GCIH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Attacking Passwords is tested as part of the GIAC Certified Incident Handler blueprint. Practicing with targeted Attacking Passwords questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCIH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Attacking Passwords is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Attacking Passwords practice session with instant scoring and detailed explanations.
Start Attacking Passwords Practice →