Courseiva

CCNA Attacking Passwords Questions

24 questions · Attacking Passwords · All types, answers revealed

1
MCQmedium

Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?

A.SHA-256; risk of collision attacks
B.NTLM; risk of credential theft and lateral movement
C.bcrypt; risk of slow brute-force degradation
D.Kerberos TGT; risk of Golden Ticket generation
AnswerB

Hashcat mode 1000 is standard for NTLM. NTLM is the legacy authentication protocol in Windows, and obtaining the plaintext password or the hash allows an attacker to impersonate the user, move laterally through the network, or escalate privileges within an Active Directory forest.

Why this answer

The exhibit identifies the use of mode 1000, which corresponds to NTLM hashes. The command uses attack mode 0 (straight dictionary attack). This combination is highly effective against Windows networks where NTLM is utilized.

The risk is that if the NTLM hash is cracked, the attacker gains the user's secret, allowing for lateral movement or privilege escalation across the entire Windows domain environment using pass-the-hash or direct authentication.

Exam trap

Candidates often focus on the hash type and forget the 'risk' aspect. They identify NTLM but fail to connect it to the specific threat of lateral movement in Windows domains.

2
MCQhard

What is the primary vulnerability exploited by the 'Responder' tool during a network-based password attack, and why does it effectively capture sensitive information?

A.It exploits weak encryption in SMB signing
B.It intercepts plaintext passwords via ARP spoofing
C.It leverages LLMNR/NBT-NS spoofing to capture NTLM hashes
D.It performs Man-in-the-Middle on encrypted Kerberos tickets
AnswerC

Responder responds to broadcast resolution queries by claiming to be the target resource. When the Windows client tries to authenticate to the 'service', it sends its NTLM challenge-response, which Responder captures. This hash can then be cracked offline or relayed to other network resources.

Why this answer

Responder exploits the fact that Windows clients automatically broadcast name resolution requests (LLMNR/NBT-NS) when DNS resolution fails. Responder acts as an imposter, claiming to be the requested server. The client then attempts to authenticate to the attacker's machine, sending its NTLM hash.

This is effective because it exploits native, legacy Windows behavior that is often enabled by default in internal networks.

Exam trap

Candidates often overthink the technical complexity of Responder. They fail to realize it simply exploits the default, insecure behavior of Windows clients asking for name resolution via broadcast protocols.

3
MCQhard

An incident responder is investigating a compromised Linux server and finds that an attacker added a new user account with a password hash in /etc/shadow. The hash begins with $6$ and includes a salt. The attacker later cracked this hash offline. Which property of the hash allowed the attacker to crack it despite the salt?

A.The $6$ prefix indicates a weak algorithm that can be reversed mathematically to recover the password.
B.The salt is stored alongside the hash and is not secret, so the attacker could use it to compute candidate hashes for each password guess.
C.The salt was generated using a predictable pattern, allowing the attacker to precompute a rainbow table for that specific salt.
D.The hash was generated with a low iteration count, making it trivial to compute but not explaining how the salt was bypassed.
AnswerB

Salts are stored in the shadow file in plaintext alongside the hash. Their purpose is to prevent precomputed rainbow tables and to ensure identical passwords produce different hashes, but they do not slow down a targeted dictionary attack. An attacker who knows the salt can compute the hash for each candidate password and compare, so salting alone does not prevent offline cracking.

Why this answer

Salts are stored with the hash and are not secret, so they do not prevent offline dictionary or brute-force attacks. They only defeat precomputed rainbow tables and ensure unique hashes for identical passwords. An attacker who obtains the shadow file can read the salt and compute candidate hashes for each guess, eventually recovering weak passwords.

Strong, unique passwords and slow hashing algorithms are the real defenses.

Exam trap

The trap here is believing that a salted hash cannot be cracked offline, when in reality the salt is stored with the hash and only prevents precomputation, not targeted guessing.

4
MCQmedium

Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?

A.It cracks the SAM database file offline
B.It retrieves cleartext credentials from LSASS memory
C.It resets the local Administrator password
D.It clears the event logs to hide the attack
AnswerB

The command dumps the contents of LSASS memory, which often holds cleartext passwords for logged-in users, as well as NTLM hashes and Kerberos tickets. Gaining these credentials allows an attacker to move laterally throughout the domain with the privileges of the victim.

Why this answer

The 'sekurlsa::logonpasswords' command extracts cleartext passwords and NTLM hashes for all users who have recently logged into the system, directly from the LSASS memory process. This is a 'game over' scenario because the attacker gains valid, active credentials, allowing them to impersonate the user across the entire network, often without needing to perform further brute-force or cracking attacks.

Exam trap

Candidates often confuse memory dumping with network sniffing. They fail to identify that Mimikatz interacts directly with the LSASS process to extract credentials stored in system memory.

5
MCQmedium

An incident responder is investigating a breach where attackers gained initial access via a phishing email. The email contained a malicious macro that executed a PowerShell script. The script attempted to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. Which of the following techniques is the attacker most likely using, and what is the primary goal?

A.Pass-the-Hash, to authenticate to other systems using captured NTLM hashes without knowing the plaintext password.
B.Credential dumping, to obtain plaintext passwords or hashes from memory for further attacks.
C.Golden Ticket attack, to forge Kerberos ticket-granting tickets using the KRBTGT account hash.
D.Kerberoasting, to request service tickets and crack their encryption offline to obtain service account passwords.
AnswerB

Credential dumping from LSASS is a common post-exploitation technique to extract plaintext passwords, NTLM hashes, and Kerberos tickets. Attackers use tools like Mimikatz or ProcDump to access LSASS memory. The goal is to harvest credentials that can be used for lateral movement, privilege escalation, or persistence. This matches the scenario's description of extracting credentials from LSASS.

Why this answer

The attacker is performing credential dumping from LSASS to harvest credentials. This is a common step after initial access, enabling further attacks like lateral movement or privilege escalation. The other options describe different techniques that either occur after credential dumping or target different components.

Therefore, credential dumping is the correct identification.

Exam trap

The trap here is conflating credential dumping with Pass-the-Hash; dumping is the theft of credentials, while Pass-the-Hash is the use of those credentials.

6
MCQhard

A penetration tester is attempting to crack NTLM hashes captured from a Windows environment. The hashes were obtained from a memory dump of a workstation. The tester decides to use Hashcat with the mode 1000. Which of the following best describes the type of hashes being cracked and the primary reason this mode is chosen?

A.Kerberos 5 TGS-REP hashes, because mode 1000 extracts service account credentials from ticket-granting tickets.
B.NetNTLMv2 hashes, because mode 1000 captures challenge-response pairs for network authentication.
C.LM hashes, because mode 1000 is designed to crack the older LAN Manager hash format.
D.NTLM hashes, because mode 1000 is optimized for fast brute-force attacks against unsalted MD4-based hashes.
AnswerD

Hashcat mode 1000 specifically targets NTLM hashes, which are unsalted MD4 hashes of the user's password. These are fast to compute, allowing high-speed brute-force and rule-based attacks. The lack of salting means identical passwords produce identical hashes, enabling precomputed attacks and efficient cracking, which is why this mode is chosen.

Why this answer

Hashcat mode 1000 is designated for NTLM hashes, which are MD4-based and unsalted. This makes them vulnerable to rapid brute-force and dictionary attacks. The other options misidentify the hash types and their corresponding Hashcat modes.

Therefore, the correct answer is the one that correctly pairs NTLM with mode 1000 and explains the speed advantage.

Exam trap

The trap here is assuming that mode 1000 handles NetNTLMv2 or Kerberos hashes, but each hash type has a distinct mode in Hashcat.

7
MCQmedium

During an incident response engagement at a financial firm, you are reviewing authentication logs on a Windows Server 2019 domain controller. You notice a series of failed logon attempts with Event ID 4625, all originating from a single source IP, using a list of 500 common usernames but only one password attempt per username. The attempts occur over a period of 30 minutes. Which type of password attack is most likely being executed?

A.Brute-force attack
B.Password spraying
C.Credential stuffing
D.Rainbow table attack
AnswerB

Password spraying uses a small number of common passwords against many accounts to avoid lockout thresholds. Here, 500 usernames with a single password attempt each matches this pattern perfectly. It is a low-and-slow approach that evades account lockout policies, making it the most likely attack based on the log evidence.

Why this answer

The pattern of many usernames with a single password attempt each is characteristic of password spraying. This technique avoids lockout by keeping failed attempts per account low while testing a common password across many accounts. Credential stuffing uses breached pairs, brute-force targets one account, and rainbow tables are offline.

Thus, password spraying is the correct identification.

Exam trap

The trap here is confusing password spraying with brute-force, but spraying uses one password against many accounts, while brute-force uses many passwords against one account.

8
MCQeasy

Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?

A.Testing thousands of passwords against a single high-privileged account
B.Using one common password against many different accounts
C.Capturing hashes via packet sniffing and offline cracking
D.Injecting malicious code into the authentication form
AnswerB

Password spraying is characterized by the 'low and slow' approach of testing a single password against many accounts. This minimizes failed attempts per account, ensuring that individual user accounts remain active and that the attacker does not trigger account lockout mechanisms during the process.

Why this answer

Password spraying involves testing a single, common password against a large list of accounts rather than testing many passwords against one account. It is preferred because it avoids triggering account lockout thresholds, which are designed to detect traditional brute-force attacks. By keeping the authentication frequency low per account, attackers can stay under the radar of automated security monitoring systems while significantly increasing the likelihood of compromising at least one account.

Exam trap

Candidates frequently confuse password spraying with credential stuffing. They fail to realize that spraying uses one password against many accounts, whereas stuffing uses many credentials against one or more targets.

9
MCQeasy

An incident responder is analyzing a compromised Linux server and discovers that the attacker has added a new user account with a password hash in /etc/shadow. The responder notes that the hash begins with '$6$'. Which of the following best describes the hashing algorithm used for this password?

A.bcrypt
B.SHA-512 crypt
C.MD5 crypt
D.SHA-256 crypt
AnswerB

The '$6$' prefix in /etc/shadow indicates SHA-512 crypt, a widely used password hashing algorithm on Linux. It applies multiple rounds of SHA-512 with a salt to slow down brute-force attacks. Recognizing this prefix helps incident responders understand the strength of the password storage and the potential effort required to crack it.

Why this answer

In /etc/shadow, the '$6$' prefix identifies SHA-512 crypt as the hashing algorithm. This is a strong, salted, and iterated algorithm commonly used on modern Linux systems. The other prefixes correspond to different algorithms: '$1$' for MD5, '$5$' for SHA-256, and '$2a$' for bcrypt.

Correctly identifying the algorithm helps assess password cracking difficulty.

Exam trap

The trap here is confusing the numeric prefixes for SHA-256 and SHA-512 crypt, where '$5$' is SHA-256 and '$6$' is SHA-512.

10
MCQeasy

Which of the following password security practices is most effective at preventing the use of 'weak' passwords that are easily identified by dictionary attacks?

A.Mandating password changes every 90 days
B.Requiring a combination of uppercase and special characters
C.Using a banned password list during creation
D.Storing all passwords in a secure password manager
AnswerC

Banned password lists prevent users from setting passwords known to be weak or compromised. By blocking passwords found in databases like 'Have I Been Pwned', you eliminate the low-hanging fruit that dictionary attackers rely on for success.

Why this answer

Implementing a 'banned password list' (often called a common password list) checks user-chosen passwords against a database of previously leaked or commonly used passwords during the password change event. This prevents users from selecting passwords that are trivial to crack via dictionary attacks, effectively shifting the user base toward higher-entropy, more secure credentials.

11
MCQmedium

During an internal penetration test, you capture SMB traffic between a user workstation and a file server on the same Layer 2 segment. The captured exchange shows the client sending an authentication request containing a username and a challenge/response value, but no cleartext password. You want to recover the user's cleartext password offline using a wordlist. Which attack technique should you apply to the captured challenge/response pair?

A.Extract the user's NT hash from the capture and submit it to a Pass-the-Hash tool to authenticate to the file server.
B.Decrypt the SMB session with the server's machine account key to reveal the user's password from the encrypted payload.
C.Perform an offline dictionary attack against the captured NTLMv2 challenge/response using a tool such as Hashcat with mode 5600.
D.Replay the captured challenge/response value directly to the file server to authenticate as the user without cracking it.
AnswerC

The captured material is an NTLMv2 challenge/response (NetNTLMv2), and Hashcat mode 5600 is designed specifically to crack NetNTLMv2 hashes offline against a wordlist. Because the challenge/response is derived from the user's password, guessing passwords and recomputing the response lets you recover the cleartext password without touching the live server.

Why this answer

The captured exchange is a NetNTLMv2 authentication, which exposes a challenge/response rather than a cleartext password or NT hash. To recover the cleartext password, an attacker performs an offline dictionary or brute-force attack against that response using a tool configured for NetNTLMv2, such as Hashcat mode 5600. This avoids further interaction with the target and does not trigger account lockouts on the server.

Exam trap

The trap here is assuming that a captured NTLM challenge/response can be relayed back to the same server or used directly as an NT hash, when in fact it must be cracked offline or relayed to a different target.

12
MCQmedium

An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the responder needs to prioritize cracking accounts with weak passwords using Hashcat. Which hash mode should be explicitly specified for cracking standard Windows NT LAN Manager (NTLM) password hashes extracted from this database?

A.Mode 3000, which is designated for legacy LAN Manager hashes.
B.Mode 5600, which targets NetNTLMv2 network authentication captures.
C.Mode 1000, which corresponds directly to standard NTLM password hashes.
D.Mode 13100, which is utilized for Kerberos 5 TGS-REP etype 23 tickets.
AnswerC

Hashcat utilizes mode 1000 specifically for NTLM hashes extracted from Windows operating system password databases. Providing this exact numerical identifier allows the cracking utility to properly parse the user account records and execute high-speed GPU-accelerated dictionary and rule-based attacks.

Why this answer

Hashcat mode 1000 specifically targets NTLM password hashes, which are stored within the NTDS.dit database. Modern Windows environments heavily rely on NTLM for authentication fallback and pass-the-hash attacks, making these hashes critical targets for offline cracking during incident response engagements. Accurately identifying and utilizing the correct hash algorithm identifier ensures that computing resources are focused efficiently without wasting time on incompatible parsing formats.

Exam trap

Candidates often confuse NTLM (mode 1000) with older LAN Manager hashes (mode 3000) or newer NetNTLMv2 challenge-response network authentication captures (mode 5600), leading to incorrect command execution.

13
MCQhard

An incident responder is reviewing logs from a Windows environment and finds that an attacker obtained the NT hash of a domain administrator through a credential dumping technique. The attacker then used that hash to authenticate to multiple servers without ever knowing the cleartext password. Which condition allowed this Pass-the-Hash authentication to succeed?

A.The target servers accepted NTLM authentication and the attacker supplied the NT hash directly as the response to the server challenge.
B.Kerberos was enforced across the domain, allowing the attacker to request a service ticket using the NT hash as the long-term key.
C.The attacker had previously obtained the cleartext password and used it to derive the NT hash on each target server.
D.The servers were configured to cache credentials in LSASS, which allowed the attacker to reuse the cached hash for authentication.
AnswerA

Pass-the-Hash works because NTLM authentication only requires the NT hash to compute the challenge/response, not the cleartext password. When a server accepts NTLM, an attacker who possesses the NT hash can supply it to generate a valid response. This is why obtaining the hash is often equivalent to obtaining the password for authentication purposes in NTLM-enabled environments.

Why this answer

Pass-the-Hash succeeds because NTLM authentication relies on the NT hash to compute the challenge/response and never requires the cleartext password. Once an attacker extracts the NT hash, they can authenticate to any NTLM-accepting service as that user. Defenses include disabling NTLM, enforcing Kerberos, implementing credential Guard, and restricting privileged account logons to specific hardened hosts.

Exam trap

The trap here is confusing Pass-the-Hash with Overpass-the-Hash, which uses the hash to obtain Kerberos tickets; Pass-the-Hash specifically leverages NTLM authentication.

14
MCQhard

When analyzing a compromised system, you find evidence of 'Kerberoasting'. What is the primary objective of this attack, and what specific artifact is the attacker attempting to acquire?

A.Acquiring the TGT; goal is to forge Golden Tickets
B.Acquiring the TGS; goal is to crack service account passwords
C.Acquiring the NTLM hash; goal is Pass-the-Hash
D.Acquiring the PAC; goal is privilege escalation
AnswerB

Kerberoasting involves requesting TGS tickets for SPN-enabled accounts. These tickets are encrypted with the account's password hash. Offline cracking of these tickets reveals the plaintext password, allowing the attacker to escalate privileges if the service account has excessive permissions on the network.

Why this answer

The primary objective of Kerberoasting is to obtain service tickets for service accounts with Service Principal Names (SPNs). The attacker requests a TGS (Ticket Granting Service) ticket for a service account, which is encrypted using the account's password hash. By extracting this ticket, the attacker can move the data offline and attempt to crack the password hash without further interaction with the Domain Controller, avoiding detection by account lockout policies.

Exam trap

Candidates often think the goal is to gain immediate entry to the Domain Controller, rather than understanding that the TGS is used for offline password cracking.

15
MCQmedium

During an incident response engagement, you capture SMB authentication traffic on a subnet where an attacker has positioned a rogue device. The traffic shows NTLMv2 challenge/response pairs being relayed to a file server that does not enforce SMB signing. Which of the following best describes the security control that would have most directly prevented the relayed authentication from succeeding?

A.Enabling Extended Protection for Authentication on the domain controller
B.Enforcing SMB signing on the target file server
C.Disabling NetBIOS over TCP/IP on all workstations
D.Requiring Kerberos authentication for all domain logons
AnswerB

SMB signing cryptographically binds each message to the session key derived from the authentication exchange, so a relayed authentication cannot be reused to establish a new session. When the file server requires signing and the client cannot sign, the session fails. This directly breaks the NTLM relay because the attacker cannot produce valid signatures without possessing the session key.

Why this answer

SMB signing is the specific control that prevents NTLM relay to SMB file servers because it requires the client and server to sign every message with a session key. A relayed authentication cannot satisfy signing because the attacker does not possess the negotiated session key. Other controls like disabling NetBIOS or requiring Kerberos do not address the fundamental relay path over SMB.

Exam trap

The trap here is assuming that requiring Kerberos or disabling NetBIOS eliminates NTLM relay, when NTLM fallback over SMB remains viable unless SMB signing is enforced.

16
MCQmedium

An incident handler is reviewing compromised Active Directory domain credentials and notices that an attacker successfully recovered the cleartext password of a service account using an offline cracking tool. Which specific technique did the attacker most likely leverage to target this non-user domain object?

A.AS-REP Roasting targeting user accounts with Kerberos pre-authentication disabled.
B.NTLM relaying against local SMB signing configurations.
C.Pass-the-Hash utilizing harvested NTLM password hashes from memory.
D.Kerberoasting by requesting a service ticket for an SPN and cracking it offline.
AnswerD

Kerberoasting leverages any standard domain user account to request a service ticket for an arbitrary Service Principal Name, allowing attackers to export the ticket and crack the underlying service account password completely offline.

Why this answer

Kerberoasting allows any authenticated domain user to request a Service Principal Name ticket, extract the service ticket encrypted with the target service account's NTLM hash, and crack it offline without generating account lockout events. This represents a primary threat for enterprise service accounts utilizing weak passwords.

Exam trap

Candidates often confuse Kerberoasting with AS-REP Roasting; however, AS-REP Roasting targets user accounts configured with pre-authentication disabled, whereas Kerberoasting specifically targets service accounts possessing assigned Service Principal Names.

17
Multi-Selecthard

An attacker has obtained a set of NTLM hashes from a compromised workstation and now wants to use them to authenticate to other systems in the domain without cracking them. Which two of the following conditions are necessary for a successful Pass-the-Hash attack? (Choose two.)

Select 2 answers
A.The target systems must be domain controllers.
B.The target systems must accept NTLM authentication.
C.The attacker must know the plaintext password associated with the hash.
D.The NTLM hash must correspond to a user account with logon rights on the target systems.
E.The attacker must have administrative privileges on the target systems.
AnswersB, D

Pass-the-Hash relies on the NTLM authentication protocol. If target systems are configured to only accept Kerberos authentication, the attack will fail. Therefore, NTLM must be enabled and permitted on the target systems for the hash to be used directly for authentication. This is a fundamental requirement for the attack to succeed.

Why this answer

Pass-the-Hash requires that the target systems accept NTLM authentication and that the compromised hash belongs to an account with logon rights on those systems. Without these, the attack cannot proceed. Administrative privileges, plaintext passwords, and domain controller status are not necessary conditions, making them incorrect choices.

Exam trap

The trap here is thinking Pass-the-Hash requires administrative rights or the plaintext password, but it only requires a valid hash and NTLM-enabled target.

18
MCQeasy

A security analyst is reviewing password hashes extracted from an older Linux system. The hashes are stored in /etc/shadow and begin with the prefix $1$. The analyst wants to determine the hashing algorithm used so they can choose the correct cracking mode. Which algorithm is indicated by the $1$ prefix?

A.SHA-512 crypt
B.SHA-256 crypt
C.bcrypt
D.MD5 crypt
AnswerD

In Linux shadow files, the $1$ prefix denotes MD5 crypt, a legacy hashing scheme that is fast and therefore weak against modern cracking. Recognizing this prefix is important because it tells the analyst to select the corresponding mode in cracking tools and to recommend migration to a stronger algorithm such as yescrypt or SHA-512 crypt.

Why this answer

Linux shadow file prefixes identify the hashing algorithm: $1$ is MD5 crypt, $5$ is SHA-256 crypt, $6$ is SHA-512 crypt, and $2a$/$2b$/$2y$ is bcrypt. MD5 crypt is a legacy scheme that is fast to compute and therefore easily cracked with modern hardware. Analysts should recognize these prefixes to select the correct cracking mode and to advise upgrading to stronger algorithms.

Exam trap

The trap here is assuming that any dollar-sign prefix indicates a strong modern hash, when the low $1$ value actually signals the weak legacy MD5 crypt scheme.

19
MCQmedium

When performing a password audit, you identify the use of 'PBKDF2-HMAC-SHA256' for credential storage. What makes this a strong choice compared to basic salted hashes, and how does it specifically hinder offline attacks?

A.It uses hardware-specific instructions to prevent GPU cracking
B.It stretches the password, making individual guesses slow
C.It encrypts the hash so it cannot be decrypted
D.It requires a secret key that is stored on a HSM
AnswerB

Key stretching algorithms like PBKDF2 force the hashing operation to run thousands of times. This dramatically increases the computational cost of testing a single password candidate, which slows down offline cracking attacks by orders of magnitude compared to un-stretched hash functions.

Why this answer

PBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm that applies a pseudorandom function repeatedly to the input password and salt. This 'stretching' makes the process intentionally slow. By increasing the iteration count, defenders force the attacker to expend significantly more CPU time for each guess, making brute-force or dictionary attacks prohibitively slow compared to standard hashing methods.

Exam trap

Candidates often confuse key stretching with simple encryption or salting. They fail to identify that the primary purpose is specifically increasing the computational cost to make brute-force attacks slower.

20
Multi-Selectmedium

A penetration tester is performing a password attack against an Active Directory environment. The tester has obtained a list of valid domain usernames and wants to identify accounts with weak passwords without locking out accounts. The domain account lockout policy is set to lock accounts after five failed attempts within 30 minutes. Which two of the following techniques would allow the tester to test passwords while minimizing the risk of account lockout? (Choose two.)

Select 2 answers
A.Using a pass-the-hash attack with captured NTLM hashes
B.Using a tool that performs a single authentication attempt per account per lockout window
C.Brute-forcing each account with a large dictionary until a valid password is found
D.Password spraying with a single common password against all accounts, waiting between attempts
E.Performing a credential stuffing attack using passwords from previous breaches
AnswersB, D

Limiting each account to one failed attempt per lockout window ensures the account never reaches the lockout threshold. Tools like Spray or custom scripts can enforce this by tracking attempts and waiting the requisite time. This approach allows the tester to test one password per account per window, gradually building a list of valid credentials without locking accounts.

Why this answer

Password spraying and single-attempt-per-window techniques are both designed to test passwords while staying under lockout thresholds. Spraying uses one password across many accounts, and single-attempt-per-window limits each account to one guess per lockout period. Both avoid triggering the five-failure lockout, unlike brute-forcing or credential stuffing, which can rapidly exceed the threshold.

Exam trap

The trap here is assuming that any password attack can be made lockout-safe with delays, when in fact only techniques that limit attempts per account per lockout window truly avoid lockouts.

21
MCQmedium

Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?

A.Pass-the-Hash; 0xC000006A means the hash is expired
B.Brute-force/Dictionary attack; 0xC000006A means bad password
C.Account lockout; 0xC000006A means account is disabled
D.Kerberoasting; 0xC000006A means SPN not found
AnswerB

Repeated failed logins for an account, especially an administrator account, using NTLM indicate a brute-force or dictionary attack. The sub-status code 0xC000006A is the standard Windows error for an incorrect password provided during the authentication process.

Why this answer

Event ID 4625 with sub-status 0xC000006A indicates a failed logon due to a bad password. When this appears repeatedly from a single source for an administrative account, it strongly suggests a brute-force or dictionary attack. The NTLM authentication process indicates that the attacker is attempting to authenticate using the legacy NTLM protocol, which is a common indicator of targeted attacks against Windows environments.

Exam trap

Candidates often misinterpret Event ID 4625 sub-statuses. They may guess account lockout when the code specifically points to a bad password, indicating an active guessing attempt.

22
MCQhard

Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?

A.Salting increases the length of the hash, causing buffer overflows
B.Salts make the total hash space too large to compute
C.Salts negate the precomputed nature of rainbow tables
D.Salts slow down the hashing algorithm significantly
AnswerC

Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.

Why this answer

Rainbow tables are precomputed tables of hashes for all possible plaintext passwords within a specific character set. By adding a random, per-user salt before hashing, the final hash becomes dependent on both the password and the salt. This means an attacker would need to build a new rainbow table for every unique salt, rendering precomputed tables computationally useless.

Exam trap

Candidates often incorrectly assume salts make hashes impossible to crack, rather than understanding that salts specifically break the efficiency of precomputed rainbow tables.

23
MCQeasy

A security analyst is reviewing password policies for a Windows Active Directory environment. The current policy requires a minimum length of 8 characters and complexity. However, the organization wants to improve resistance against brute-force attacks. Which of the following changes would most effectively increase the time required for an offline brute-force attack against NTLM hashes?

A.Enable account lockout after 5 failed attempts.
B.Increase the minimum password length to 14 characters.
C.Set the maximum password age to 30 days.
D.Enforce password history of 24 passwords.
AnswerB

Increasing password length exponentially increases the number of possible combinations, making brute-force attacks significantly slower. For NTLM hashes, which are fast to compute, length is the most effective defense. A 14-character password has vastly more entropy than an 8-character one, directly increasing cracking time. This change is the most impactful for resisting offline attacks.

Why this answer

For offline brute-force attacks against NTLM hashes, password length is the most critical factor because it exponentially increases the search space. Other policies like history, age, and lockout are useful for online attacks but do not significantly hinder offline cracking. Thus, increasing the minimum length to 14 characters is the most effective change.

Exam trap

The trap here is focusing on lockout or complexity, but offline attacks ignore lockout and length is the dominant factor in resisting brute-force.

24
MCQmedium

Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?

A.Dictionary attacks use compromised lists; stuffing uses random passwords
B.Stuffing tests leaked credentials; dictionary attacks guess passwords
C.Dictionary attacks are faster than credential stuffing
D.Stuffing targets the database; dictionary attacks target the login
AnswerB

Credential stuffing exploits the human tendency to reuse passwords by automating logins with verified pairs from other breaches. Dictionary attacks are purely probabilistic attempts to guess a password for a single target, making them fundamentally different in execution and success rates.

Why this answer

Credential stuffing uses previously leaked username/password pairs from one service to gain unauthorized access to another. It differs from a dictionary attack because it utilizes valid, known credentials rather than guessing passwords. This is highly effective because users often reuse passwords across multiple sites, making it a critical threat to organizations that do not enforce multifactor authentication (MFA) or monitor for logins from unusual locations.

Exam trap

Candidates often confuse credential stuffing with dictionary attacks, failing to realize that stuffing relies on the reuse of valid leaked credentials rather than brute-forcing new passwords.

Ready to test yourself?

Try a timed practice session using only Attacking Passwords questions.