PEN-200 › Password Attacks
This domain covers credential capture and offline cracking across Windows and Linux targets: NetNTLMv2 challenge-response, AS-REP Roasting, Kerberoasting, /etc/shadow hashes, and encoded credentials in cookies. PEN-200 tests whether you can identify the hash or encoding format, choose the correct tool and mode, and recover plaintext to pivot or escalate.
PEN-200 Password Attacks — All 38 Questions
Every question in this domain with answers and detailed explanations.