Courseiva

CEH Enumeration and System Hacking Practice Question

Which THREE of the following are password cracking techniques that can be used with Hashcat? (Select 3)

⚠ Common exam trap

EC-Council often tests the misconception that rainbow table attacks are a core Hashcat feature, but Hashcat does not implement rainbow tables; it uses GPU-accelerated brute-force, dictionary, and hybrid modes instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack

Hashcat is a GPU-accelerated password recovery tool whose core attack modes include brute-force (option B), where it exhaustively tries every possible character combination within a defined mask or keyspace, and dictionary attack (option D), where it hashes each word from a wordlist and compares it to the target hash. Hashcat also supports hybrid attack (option E), which combines a wordlist with a mask (e.g., appending digits or symbols to dictionary words) to cover mangled passwords, invoked with modes like -a 6 and -a 7. Rainbow table attack (option C) is a legitimate cracking technique in general, but it is not a Hashcat attack mode because Hashcat computes hashes on the fly rather than looking them up in precomputed chains. Token impersonation (option A) is a Windows privilege-escalation technique involving stolen access tokens, not a password cracking method, so it is unrelated to Hashcat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Token impersonation

    Why it's wrong here

    Token impersonation is a post-exploitation technique where an attacker, having already gained initial access, leverages an existing security token from a legitimate user or process to elevate their privileges within the system. This method bypasses the need to crack a password entirely, as it relies on the operating system's trust in the token's authenticity for authorization. Therefore, it is a privilege escalation technique, not a method for discovering a user's plaintext password.

  • ✓

    Brute-force attack

    Why this is correct

    A brute-force attack systematically attempts every possible character combination for a password until the correct one is found by hashing each guess and comparing it to the target hash. This method involves defining a character set (e.g., lowercase, uppercase, numbers, symbols) and a maximum length, then iteratively generating and testing each permutation. While guaranteed to eventually succeed, its computational cost grows exponentially with password length and complexity, making it impractical for very strong passwords.

  • ✗

    Rainbow table attack

    Why it's wrong here

    A rainbow table attack utilizes precomputed tables of hash chains to reverse cryptographic hashes back into their original plaintext passwords without needing to perform the computationally intensive cracking process for each attempt. Instead of guessing passwords and hashing them, the attacker looks up the target hash in the table to find a matching chain and reconstruct the original password. This technique is highly effective against unsalted hashes but becomes ineffective when salts are used, as each salted hash would require a unique rainbow table.

  • ✓

    Dictionary attack

    Why this is correct

    A dictionary attack attempts to crack passwords by comparing target hashes against a predefined list of common words, phrases, and previously leaked passwords. This method leverages the human tendency to choose simple, memorable passwords found in dictionaries or public data breaches. It is significantly faster and more efficient than brute-force for weak passwords but will fail against strong, unique passwords not present in the wordlist.

  • ✓

    Hybrid attack

    Why this is correct

    A hybrid attack combines elements of both dictionary and brute-force attacks to target passwords that are variations of common words. This technique typically takes a word from a dictionary and systematically appends or prepends numbers, symbols, or other characters, or applies common capitalization patterns. For example, it might test 'password123', 'Password!', or 'P@ssword' against a target hash, effectively targeting users who slightly modify dictionary words.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.