Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
Start practicing
Password Attacks — choose a session length
Free · No account required
Domain overview
This domain covers credential capture and offline cracking across Windows and Linux targets: NetNTLMv2 challenge-response, AS-REP Roasting, Kerberoasting, /etc/shadow hashes, and encoded credentials in cookies. PEN-200 tests whether you can identify the hash or encoding format, choose the correct tool and mode, and recover plaintext to pivot or escalate.
Exam objectives
Recognizing hash formats such as NetNTLMv2, AS-REP, Kerberoast, and Linux crypt(3) identifiers like $6$
Selecting Hashcat modes and John the Ripper formats for each captured hash type
Using Responder, Impacket, and Mimikatz to capture or request credentials in Active Directory
Identifying weak encoding like base64 in cookies versus actual encryption or hashing
Treating base64-encoded credentials as secure encryption instead of trivially reversible encoding.
Using the wrong Hashcat mode or John format, so cracking fails despite a valid hash and wordlist.
Confusing AS-REP Roasting with Kerberoasting; AS-REP requires no Kerberos pre-authentication on the target account.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?
2Refer to the exhibit. What is the primary purpose of the command provided?
3You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?
4During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?
5Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?
6Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?
7You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?
8In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?
9Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?
10When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?
11During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?
12You compromise a Windows host and dump local account hashes with secretsdump, obtaining the NTLM hash of a local administrator. That same local administrator password was reused across every workstation in the environment. Which technique most directly allows lateral movement to other hosts using that hash without ever recovering the cleartext password?
13You have obtained a copy of a Windows SAM file from a compromised host. You want to extract the NTLM hashes for offline cracking. Which of the following tools is specifically designed for this task?
14You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)
15You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?
16During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?
17You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?
18During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?
19You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?
20You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?
21You are conducting a penetration test and have obtained a list of usernames. You want to perform a password spray against an OWA (Outlook Web Access) portal. Which tool is specifically designed to automate password spraying against OWA while respecting lockout policies?
22You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?
23During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?
Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
The Courseiva PEN-200 question bank contains 23 questions in the Password Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Password Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included