Courseiva

CEH Enumeration and System Hacking Practice Question

Which TWO of the following are password cracking techniques? (Select 2)

⚠ Common exam trap

Test-takers frequently confuse passive or indirect attacks (like phishing or ARP spoofing) with actual password cracking techniques, forgetting that cracking specifically involves recovering plaintext from hashed or encrypted representations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rainbow table attack

A rainbow table attack (B) is a password cracking technique that uses precomputed hash chains to reverse cryptographic hash functions and recover plaintext passwords quickly, trading computation time for storage space. A dictionary attack (E) is also a password cracking technique that systematically tries words from a predefined wordlist, often with mutations, against a password hash or login to guess the correct password. The other options are not password cracking techniques: SQL injection (A) is a web application injection attack that manipulates database queries, phishing (C) is a social engineering attack that tricks users into revealing credentials, and ARP spoofing (D) is a network attack that poisons ARP caches to intercept traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a code injection technique used to attack data-driven applications, where malicious SQL statements are inserted into an entry field for execution. It primarily targets the underlying database to retrieve, modify, or delete data, or even gain administrative control over the database server. While it can lead to the disclosure of password hashes stored in a database, it is a method of exfiltrating data, not a technique for computationally cracking those hashes to reveal the original passwords. Therefore, it is a database exploitation method, not a password cracking technique itself.

  • ✓

    Rainbow table attack

    Why this is correct

    A Rainbow table attack is a precomputation technique used to reverse cryptographic hash functions, primarily for cracking passwords. It involves using large, precomputed tables that map hash values back to potential plaintext passwords, significantly reducing the time required compared to brute-force attacks. These tables store chains of hash values and their corresponding plaintext representations, allowing an attacker to quickly look up a given password hash and retrieve the original password, especially effective against unsalted hashes due to its time-memory tradeoff.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering technique where attackers attempt to trick individuals into divulging sensitive information, such as usernames and passwords, by masquerading as a trustworthy entity in an electronic communication. This method relies on deception and manipulation of human psychology rather than technical exploitation of cryptographic weaknesses or computational guessing. While it aims to obtain passwords, it does not involve the computational process of cracking a hash or encrypted password to discover its original form.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing, also known as ARP poisoning, is a man-in-the-middle (MITM) attack technique where an attacker sends falsified Address Resolution Protocol (ARP) messages over a local area network. This allows the attacker to associate their MAC address with the IP address of another host, such as the default gateway, causing traffic intended for the legitimate host to be redirected through the attacker's machine. While it can facilitate eavesdropping on network traffic to potentially capture password hashes or credentials, it is a network interception technique and not a method for computationally cracking those passwords.

  • ✓

    Dictionary attack

    Why this is correct

    A dictionary attack is a password cracking technique that attempts to guess passwords by systematically trying all words in a predefined list, known as a dictionary or wordlist. This list typically includes common words, phrases, names, and previously leaked passwords, often combined with simple variations like numbers or special characters. It is a more efficient method than a pure brute-force attack when users choose weak, common, or easily guessable passwords, as it leverages human tendencies in password creation to find matches against stored hashes.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.