You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.
Start practicing
Advanced Password Attacks — choose a session length
Free · No account required
Domain overview
This domain covers credential theft and cracking on Windows/AD networks: LLMNR/NBT-NS poisoning to capture Net-NTLMv2, Kerberos pre-auth attacks (AS-REP roasting, Kerberoasting), and offline hash recovery with Hashcat/John. GPEN tests your ability to choose the right capture technique, hash mode, and post-capture step under time pressure.
Exam objectives
Responder LLMNR/NBT-NS poisoning to capture Net-NTLMv2 hashes on internal networks
Hashcat modes for Net-NTLMv2 (5600) and Kerberos AS-REP (18200) offline cracking
Kerberos AS-REP roasting against accounts without pre-authentication enabled
Kerberoasting via SPN enumeration and TGS-REP extraction for offline cracking
Using the wrong Hashcat mode for Net-NTLMv2 (e.g., 1000 instead of 5600), causing failed or invalid cracking attempts.
Confusing AS-REP roasting (no pre-auth) with Kerberoasting (requires SPN and valid credentials), leading to wrong tooling and targets.
Assuming captured Net-NTLMv2 can be relayed or cracked quickly; weak wordlists and no rules often yield no plaintext.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
2Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?
3Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?
4Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?
5In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?
6Which THREE conditions must be met for a successful AS-REP Roasting attack?
7What is the primary risk associated with storing credentials in plain text within scripts or configuration files?
8During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?
9During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)
10During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?
11During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?
12During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?
13When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)
14A penetration tester has obtained a single NT hash for a domain user account during an internal engagement. The tester wants to authenticate to a remote Windows 10 workstation as that user without knowing the plaintext password. Which tool is designed to perform this authentication using only the NT hash?
15During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a workstation. You attempt to crack it offline using Hashcat, but after several hours with a large wordlist and rules, the hash remains uncracked. Which factor most directly determines the feasibility of cracking this hash?
16A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)
17During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?
18A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?
19During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?
20A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)
21A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?
22A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?
23During a penetration test, an operator captures a network authentication attempt using the NTLMv2 protocol. The operator wants to crack the captured challenge-response offline using Hashcat. Which hash mode should the operator select to correctly process the captured NetNTLMv2 hash?
24During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?
25A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?
26A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)
You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.
The Courseiva GPEN question bank contains 26 questions in the Advanced Password Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Advanced Password Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included