Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
Start practicing
Password Attacks and Formats — choose a session length
Free · No account required
Domain overview
This GPEN domain covers how credentials are stored, captured, and cracked during penetration tests. You must recognize hash formats, understand salting and cleartext exposure risks, and select appropriate tools such as Hashcat, John the Ripper, and Mimikatz to recover or reuse credentials.
Exam objectives
Identifying hash types by length and format, such as MD5, NTLM, and bcrypt
Using Hashcat and John the Ripper with correct modes and wordlists
Recognizing cleartext credential exposure in environment variables and config files
Applying salts to defeat rainbow tables and identical-password correlation
Assuming any 32-character hex string is NTLM when it may be MD5, leading to wrong cracking mode
Believing salts make hashes uncrackable rather than just defeating precomputed rainbow tables
Forgetting that cleartext credentials in config files or environment variables require no cracking at all
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?
2Which TWO of the following password cracking techniques are considered 'offline' attacks?
3What is the primary security advantage of utilizing salts in password hashing?
4Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?
5What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
6What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?
7Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?
8When performing a penetration test, why is it safer to crack hashes offline rather than online?
9A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?
10A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?
11During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?
12During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?
13A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?
14During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?
15A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?
16During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?
17A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)
18A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?
19A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?
Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
The Courseiva GPEN question bank contains 19 questions in the Password Attacks and Formats domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Password Attacks and Formats domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included