Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.
Start practicing
Attacking Password Hashes — choose a session length
Free · No account required
Domain overview
This domain covers extracting and cracking Windows credential material: NTLM and NTLMv2 hashes, LSASS and SAM dumps, and offline attacks with Hashcat and John the Ripper. GPEN questions present a capture or dump scenario and ask which technique, tool, or cracking mode is correct for recovering plaintext or abusing the hash.
Exam objectives
Distinguishing NTLM hash cracking from NTLMv2 challenge-response cracking and their Hashcat modes
Using Mimikatz or similar tooling to dump LSASS and extract credential material
Extracting and parsing SAM/SYSTEM hives with secretsdump, pwdump, or samdump2
Choosing offline brute-force, dictionary, or rule-based attacks against captured hashes
Treating NTLMv2 challenge-response pairs as crackable NTLM hashes; they require a different Hashcat mode and network capture context
Assuming LSASS dumping always yields plaintext; it may only return NTLM hashes needing cracking or pass-the-hash
Confusing SAM extraction tools with cracking tools, or forgetting the SYSTEM hive is needed to decrypt SAM hashes
Click any question to see the full explanation and answer options, or start a focused practice session above.
When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?
2Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?
3During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?
4Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?
5Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?
6Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?
7Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?
8During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?
9During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?
10During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?
11During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?
12A penetration tester has obtained a set of Linux shadow file hashes. The hashes begin with $6$ and the tester intends to perform an offline brute-force attack using Hashcat. Which mode should the tester select to ensure Hashcat correctly interprets these hashes?
13A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)
14You are conducting an internal penetration test and have obtained a set of NTLM hashes from a compromised server. You want to crack them using Hashcat on a dedicated GPU rig. Which hash mode should you use?
15A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?
16A penetration tester captures a NetNTLMv2 hash from a network segment using Responder. The tester wants to crack this hash using Hashcat. Which Hashcat mode should be used?
17During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?
18During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?
19A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?
20A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?
21A penetration tester is performing an offline attack against a Kerberos TGS-REP hash obtained via Kerberoasting. Which of the following Hashcat modes should be used?
22During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?
23A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)
Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.
The Courseiva GPEN question bank contains 23 questions in the Attacking Password Hashes domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Attacking Password Hashes domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included