GCIH · domain
Attacking Passwords
This GCIH domain covers credential theft and offline cracking on Windows and Linux targets. You must recognize Mimikatz modules, LSASS and NTDS.dit dumping, NTLM relay, and hashcat/John usage, then map observed artifacts and sub-status codes to the correct attack technique during incident response.
Focused practice
Practice Attacking Passwords questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Attacking Passwords
Be able to identify credential-dumping and relay techniques from artifacts, and choose the right cracking or reuse path. The key: distinguish stored NT hashes usable for pass-the-hash from NTLMv2 network responses that must be cracked or relayed.
Mimikatz sekurlsa::logonpasswords extracting plaintext credentials and NTLM hashes from LSASS memory
NTDS.dit extraction from domain controllers and offline cracking with hashcat or John the Ripper
NTLMv2 challenge/response relay via Responder and ntlmrelayx against SMB file servers
Windows logon sub-status codes and event log entries indicating pass-the-hash or brute force
Watch out for
Common Attacking Passwords exam traps
- ▸Assuming NTLM hashes must be cracked before use; pass-the-hash allows authentication with the hash directly, no plaintext needed.
- ▸Confusing LM, NTLM, and NTLMv2 challenge/response values; only the NetNTLMv2 response is relayed or cracked offline, not the stored NT hash.
- ▸Treating LSASS dumping as requiring admin on modern Windows; credential dumping protections and PPL change what access and tooling are needed.
Question index
All Attacking Passwords questions (24)
Click any question to see the full explanation, or start a practice session above.
Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?
Medium2What is the primary vulnerability exploited by the 'Responder' tool during a network-based password attack, and why does it effectively capture sensitive information?
Hard3An incident responder is investigating a compromised Linux server and finds that an attacker added a new user account with a password hash in /etc/shadow. The hash begins with $6$ and includes a salt. The attacker later cracked this hash offline. Which property of the hash allowed the attacker to crack it despite the salt?
Hard4Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?
Medium5An incident responder is investigating a breach where attackers gained initial access via a phishing email. The email contained a malicious macro that executed a PowerShell script. The script attempted to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. Which of the following techniques is the attacker most likely using, and what is the primary goal?
Medium6A penetration tester is attempting to crack NTLM hashes captured from a Windows environment. The hashes were obtained from a memory dump of a workstation. The tester decides to use Hashcat with the mode 1000. Which of the following best describes the type of hashes being cracked and the primary reason this mode is chosen?
Hard7During an incident response engagement at a financial firm, you are reviewing authentication logs on a Windows Server 2019 domain controller. You notice a series of failed logon attempts with Event ID 4625, all originating from a single source IP, using a list of 500 common usernames but only one password attempt per username. The attempts occur over a period of 30 minutes. Which type of password attack is most likely being executed?
Medium8Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?
Easy9An incident responder is analyzing a compromised Linux server and discovers that the attacker has added a new user account with a password hash in /etc/shadow. The responder notes that the hash begins with '$6$'. Which of the following best describes the hashing algorithm used for this password?
Easy10Which of the following password security practices is most effective at preventing the use of 'weak' passwords that are easily identified by dictionary attacks?
Easy11During an internal penetration test, you capture SMB traffic between a user workstation and a file server on the same Layer 2 segment. The captured exchange shows the client sending an authentication request containing a username and a challenge/response value, but no cleartext password. You want to recover the user's cleartext password offline using a wordlist. Which attack technique should you apply to the captured challenge/response pair?
Medium12An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the responder needs to prioritize cracking accounts with weak passwords using Hashcat. Which hash mode should be explicitly specified for cracking standard Windows NT LAN Manager (NTLM) password hashes extracted from this database?
Medium13An incident responder is reviewing logs from a Windows environment and finds that an attacker obtained the NT hash of a domain administrator through a credential dumping technique. The attacker then used that hash to authenticate to multiple servers without ever knowing the cleartext password. Which condition allowed this Pass-the-Hash authentication to succeed?
Hard14When analyzing a compromised system, you find evidence of 'Kerberoasting'. What is the primary objective of this attack, and what specific artifact is the attacker attempting to acquire?
Hard15During an incident response engagement, you capture SMB authentication traffic on a subnet where an attacker has positioned a rogue device. The traffic shows NTLMv2 challenge/response pairs being relayed to a file server that does not enforce SMB signing. Which of the following best describes the security control that would have most directly prevented the relayed authentication from succeeding?
Medium16An incident handler is reviewing compromised Active Directory domain credentials and notices that an attacker successfully recovered the cleartext password of a service account using an offline cracking tool. Which specific technique did the attacker most likely leverage to target this non-user domain object?
Medium17An attacker has obtained a set of NTLM hashes from a compromised workstation and now wants to use them to authenticate to other systems in the domain without cracking them. Which two of the following conditions are necessary for a successful Pass-the-Hash attack? (Choose two.)
Hard18A security analyst is reviewing password hashes extracted from an older Linux system. The hashes are stored in /etc/shadow and begin with the prefix $1$. The analyst wants to determine the hashing algorithm used so they can choose the correct cracking mode. Which algorithm is indicated by the $1$ prefix?
Easy19When performing a password audit, you identify the use of 'PBKDF2-HMAC-SHA256' for credential storage. What makes this a strong choice compared to basic salted hashes, and how does it specifically hinder offline attacks?
Medium20A penetration tester is performing a password attack against an Active Directory environment. The tester has obtained a list of valid domain usernames and wants to identify accounts with weak passwords without locking out accounts. The domain account lockout policy is set to lock accounts after five failed attempts within 30 minutes. Which two of the following techniques would allow the tester to test passwords while minimizing the risk of account lockout? (Choose two.)
Medium21Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?
Medium22Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?
Hard23A security analyst is reviewing password policies for a Windows Active Directory environment. The current policy requires a minimum length of 8 characters and complexity. However, the organization wants to improve resistance against brute-force attacks. Which of the following changes would most effectively increase the time required for an offline brute-force attack against NTLM hashes?
Easy24Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?
MediumOther domains
All GCIH exam domains
Frequently asked questions
- What does the Attacking Passwords domain cover on the GCIH exam?
- Be able to identify credential-dumping and relay techniques from artifacts, and choose the right cracking or reuse path. The key: distinguish stored NT hashes usable for pass-the-hash from NTLMv2 network responses that must be cracked or relayed.
- How many questions are in this domain?
- This page lists all 24 Attacking Passwords questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Attacking Passwords questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.