20+ practice questions focused on Password Attacks and Formats — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Password Attacks and Formats PracticeRefer to the exhibit. The penetration tester is unable to crack the hash using mode 1800. What is the most likely cause of this failure?
Explanation: The exhibit shows a SHA-512 crypt hash (indicated by the $6$ prefix). Hashcat mode 1800 targets SHA-512 based hashes, but specifically for legacy systems or custom implementations. Modern Linux SHA-512 crypt hashes require mode 1800 to be configured correctly with the specific parameters. Misidentifying the hash format leads to incorrect salt parsing and improper algorithm selection, which are critical errors when attempting to recover secrets from standard Linux password storage files.
Which THREE factors significantly influence the time required to crack a password hash during an offline attack?
Explanation: The efficiency of an offline attack is governed by the speed of the hardware, the complexity of the hash function, and the quality of the dictionary or wordlist. Modern GPUs can perform billions of hashes per second, but complex algorithms like bcrypt or Argon2 are designed to be intentionally slow. Balancing these factors is essential for planning an engagement, as it determines whether cracking a specific hash is feasible within the allotted time frame of a test.
Refer to the exhibit. Which attack method is most likely to succeed given this password policy?
Explanation: The policy has a very strict account lockout of only 3 failed attempts. This effectively makes brute-forcing a single account online nearly impossible. However, the lack of a history check or other limitations might suggest other weaknesses. Spraying is the only viable online option, but the testing focus should shift towards offline cracking or non-password-based techniques, as standard online brute force will trigger an immediate and persistent lockout for the target user.
Which hashing algorithm is currently considered the most resistant to brute-force attacks due to its design as a memory-hard function?
Explanation: Argon2 is a memory-hard function, meaning it requires significant RAM to compute, in addition to CPU cycles. This design specifically targets the hardware advantage of GPUs and ASICs, which have many cores but limited high-speed memory per core. By forcing the computation to consume large amounts of memory, Argon2 makes it prohibitively expensive to parallelize the cracking process, offering superior protection compared to older algorithms like MD5 or SHA-1.
Refer to the exhibit. What does this hash format indicate about the password for 'user1'?
Explanation: The exhibit shows a standard Windows SAM file format. The first part is the LM hash, and the second is the NTLM hash. The specific strings 'aad3b...' and '31d6c...' are the universal indicators for an empty or null password. In a penetration testing context, identifying these null hashes is a quick win, as it reveals accounts that have no password protection, allowing for immediate access without needing to run any cracking tools.
+15 more Password Attacks and Formats questions available
Practice all Password Attacks and Formats questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Password Attacks and Formats. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Password Attacks and Formats questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Password Attacks and Formats is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Password Attacks and Formats questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Password Attacks and Formats is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Password Attacks and Formats practice session with instant scoring and detailed explanations.
Start Password Attacks and Formats Practice →