Courseiva

CCNA Understanding Passwords Questions

18 questions · Understanding Passwords · All types, answers revealed

1
MCQhard

An incident handler is investigating a breach where an attacker gained access to a system that uses a password manager. The password manager stores all user passwords in an encrypted vault protected by a single master password. The attacker was able to extract the encrypted vault and is now attempting to crack the master password offline. Which of the following characteristics of the password manager's key derivation function would most significantly increase the attacker's difficulty?

A.Using a high iteration count with a memory-hard function like Argon2id.
B.Encrypting the vault with AES-256 in CBC mode.
C.Using a simple hash function like SHA-256 with a salt.
D.Storing the master password hash in a separate hardware security module (HSM).
AnswerA

Argon2id is a memory-hard key derivation function that requires significant memory and CPU resources, making it highly resistant to GPU-based cracking. A high iteration count further increases the computational cost. This combination forces the attacker to expend substantial resources for each guessing attempt, dramatically slowing down offline cracking of the master password.

Why this answer

The key derivation function used to transform the master password into an encryption key is critical. A memory-hard function like Argon2id with a high iteration count requires large amounts of memory and CPU time per guess, making offline brute-force attacks impractical. This significantly increases the cost for the attacker, even with specialized hardware.

Exam trap

The trap here is focusing on the encryption algorithm (AES-256) or hardware protection (HSM) when the primary defense against offline master password cracking is the key derivation function's memory-hardness and iteration count.

2
MCQmedium

During an incident response engagement at a financial services firm, you discover that the attacker obtained a copy of the /etc/shadow file from a compromised Linux server. The file contains hashes generated with the SHA-512 crypt scheme ($6$). Which of the following is the MOST accurate assessment of the attacker's ability to recover plaintext passwords from these hashes?

A.The attacker must perform offline cracking, and success depends on factors such as password complexity, the iteration count configured in the hash, and the attacker's available computing resources.
B.The attacker cannot recover any passwords because the presence of a salt in the hash makes brute-force attacks mathematically infeasible regardless of password strength.
C.The attacker can decrypt the hashes using the publicly available SHA-512 algorithm because the algorithm is reversible when the salt is known.
D.The attacker can immediately use the hashes to authenticate to other systems via pass-the-hash because SHA-512 crypt hashes are accepted as credentials by SSH and other services.
AnswerA

This is correct. SHA-512 crypt is a key derivation function that applies thousands of iterations by default, making each guess computationally expensive. Offline cracking is the only viable route because the hashes are not directly usable for authentication. The attacker's success hinges on the entropy of the original passwords, the number of rounds specified in the hash string, and the hardware available for brute-force or dictionary attacks.

Why this answer

The scenario describes a Linux system using SHA-512 crypt, a salted key derivation function. Because these hashes cannot be replayed for authentication, the attacker must crack them offline. The difficulty of that cracking is influenced by the password's complexity, the iteration count embedded in the hash, and the attacker's hardware.

Salting prevents rainbow tables but does not make brute force infeasible, and hashing is not reversible.

Exam trap

The trap here is assuming that possessing a password hash immediately grants authentication access, confusing offline cracking with pass-the-hash techniques that require specific protocols.

3
MCQeasy

What is the primary function of a salt in password storage?

A.To increase the length of the password string
B.To prevent precomputed rainbow table attacks
C.To encrypt the password in the database
D.To hide the algorithm type from attackers
AnswerB

Salts prevent rainbow tables by ensuring that the hash for a password like 'password123' is unique for every user. Because the attacker cannot precalculate the hashes for all possible salts, they cannot use a standard table to crack the stolen database quickly, forcing a much slower brute-force approach.

Why this answer

A salt is a random value added to a password before hashing. Its purpose is to ensure that identical passwords produce unique hash results. This prevents attackers from using precomputed tables (rainbow tables) to reverse hashes.

By forcing attackers to crack each hash individually, the salt effectively renders bulk cracking attacks against a database computationally infeasible, significantly increasing the time and resources required for a successful offline attack after an initial breach.

Exam trap

Candidates often mistakenly believe a salt is for encryption or to hide the password from the admin. Its sole purpose is to make each hash unique to prevent precomputed bulk attacks.

4
MCQhard

An incident handler is investigating a compromised web application that stores user passwords using a custom hashing scheme. The application concatenates a user-specific salt with the password and then applies the SHA-256 hash function 10,000 times. The handler notices that the salt is only 4 bytes long and is generated using a predictable random number generator. Which of the following is the most significant weakness in this password storage scheme?

A.The use of SHA-256 as the underlying hash function is insecure for password storage.
B.The custom scheme does not use a pepper, which is required for security.
C.The iteration count of 10,000 is too low for modern hardware.
D.The salt is too short and generated predictably, allowing attackers to precompute hashes.
AnswerD

A 4-byte salt provides only 2^32 possible values, which is insufficient to prevent precomputation attacks. If the salt is generated predictably, attackers can precompute hashes for common passwords with all possible salts. This defeats the purpose of salting, which is to ensure unique hashes even for identical passwords and to thwart rainbow tables.

Why this answer

The most critical weakness is the short and predictably generated salt. A salt should be unique, random, and sufficiently long (typically at least 16 bytes) to prevent attackers from precomputing hashes or using rainbow tables. With only 4 bytes and predictable generation, an attacker can easily enumerate all possible salts and crack passwords more efficiently.

The iteration count and choice of SHA-256 are secondary concerns.

Exam trap

The trap here is focusing on the iteration count or the hash algorithm while overlooking that a short, predictable salt drastically reduces the effort required to crack passwords.

5
MCQmedium

A GCIH incident handler is investigating a Windows 10 workstation compromised by an attacker who briefly gained local administrator access. The attacker ran a utility that extracted credential material while the machine was running, then left. The handler finds no suspicious files in the System32 directory, and the SAM and SYSTEM hives appear unmodified. However, the handler notices that the LSASS process was accessed by a process that is no longer running. Which of the following best describes what the attacker most likely obtained?

A.Plaintext credentials or password hashes cached in memory by the Local Security Authority Subsystem Service (LSASS).
B.The Active Directory database (NTDS.dit) from the domain controller.
C.The NTLM password hashes stored in the SAM database.
D.The DPAPI master keys used to encrypt saved browser passwords.
AnswerA

The Local Security Authority Subsystem Service (LSASS) caches credential material in memory, including plaintext passwords (if wdigest authentication is enabled), NTLM hashes, and Kerberos tickets. An attacker with local administrator rights can access LSASS and extract these credentials using tools like Mimikatz. Since the SAM hive was unmodified and no files were left on disk, the most likely target was LSASS in memory, making this the correct answer.

Why this answer

Accessing LSASS in memory allows an attacker to extract credential material that is not stored on disk, such as plaintext passwords (if wdigest is enabled), NTLM hashes, and Kerberos tickets. Because the SAM and SYSTEM hives were unmodified and no files were left behind, the attacker likely used a memory-based credential dumping technique targeting LSASS. This is a common post-exploitation step for privilege escalation and lateral movement.

Exam trap

The trap here is assuming that credential theft always involves copying the SAM database, when in fact LSASS memory often holds more valuable and volatile credentials.

6
MCQeasy

A security administrator is configuring a new web application and wants to implement a password hashing scheme that includes a pepper. Where should the pepper be stored to provide the intended security benefit?

A.In the same database table as the password hashes, but in a separate column.
B.In the user's browser as a cookie to ensure uniqueness per session.
C.In a configuration file on the application server, outside the database.
D.In the source code of the application, hardcoded as a constant.
AnswerC

A pepper is a secret value added to the password before hashing, and it should be stored separately from the password hashes, typically in a configuration file or hardware security module (HSM) on the application server. This way, even if the database is breached, the attacker cannot crack the hashes without also obtaining the pepper. Storing it outside the database provides defense in depth.

Why this answer

The pepper must be stored separately from the password hashes to be effective. If the database is compromised but the pepper is stored on the application server in a configuration file, the attacker cannot crack the hashes without also gaining access to that file. This separation provides an additional layer of defense.

Storing the pepper in the database or client-side negates its benefit.

Exam trap

The trap here is thinking that storing the pepper in a separate column of the same database is sufficient, but the database compromise would expose both the hashes and the pepper.

7
MCQmedium

Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?

A.Stored in the same database table; prevents rainbow tables
B.Stored in a separate environment variable; adds an extra layer
C.Stored in the application code; ensures performance
D.Stored in the user session; ensures unique hashes
AnswerB

Storing the pepper in a secure, separate location (like an environment variable or HSM) ensures that a database leak alone does not expose the passwords. The attacker would need both the database and access to the server's configuration/environment to have any hope of cracking the hashes.

Why this answer

A pepper is a secret value added to the password hashing process that is stored separately from the hash, typically in a secure configuration file, environment variable, or Hardware Security Module (HSM). Because the pepper is not stored in the database, an attacker who steals only the database cannot brute-force the hashes, as they lack the pepper. This creates a dual-layer dependency that significantly raises the bar for successful offline cracking attempts.

Exam trap

Many candidates confuse a pepper with a salt, incorrectly believing that a pepper should be stored alongside the password hash in the public database table rather than separately.

8
Multi-Selectmedium

An incident handler is analyzing a compromised Windows workstation and discovers that the attacker extracted password hashes from the SAM database. The handler wants to determine which types of attacks the attacker could perform using these hashes. (Choose two.)

Select 2 answers
A.Directly decrypt the NTLM hashes using the Windows Data Protection API (DPAPI) to obtain cleartext passwords.
B.Use the hashes to generate Kerberos golden tickets without any further privileges or domain compromise.
C.Pass-the-hash to authenticate to other Windows systems using the NTLM hash without knowing the plaintext password.
D.Recover the original plaintext passwords by reversing the MD5 algorithm used to store them in the SAM database.
E.Offline brute-force or dictionary attacks against the NTLM hashes to recover plaintext passwords.
AnswersC, E

This is correct. Windows NTLM authentication accepts the hash as proof of identity in certain protocols, allowing an attacker to authenticate without cracking the hash. This technique, known as pass-the-hash, is a common lateral movement method. The attacker can use tools like Mimikatz or Impacket to inject the hash into a new session and access remote resources. It does not require the plaintext password, making it a direct threat once hashes are obtained.

Why this answer

The two correct attacks are pass-the-hash and offline cracking. Pass-the-hash exploits NTLM's design to authenticate using the hash directly, enabling lateral movement without cracking. Offline cracking attempts to recover plaintext passwords for broader reuse.

DPAPI does not decrypt hashes, golden tickets require domain-level secrets, and reversing a hash algorithm is not feasible.

Exam trap

The trap here is conflating local SAM hashes with domain-level secrets, leading to overestimating the attacker's ability to forge Kerberos tickets or decrypt hashes.

9
Multi-Selectmedium

Which TWO of the following are common indicators that a password database has been compromised?

Select 2 answers
A.A high volume of account takeover reports
B.Increased server CPU usage during off-hours
C.Sudden, massive spikes in credential stuffing logs
D.A change in the local system time on the server
E.An increase in valid user password reset requests
AnswersA, C

When a large number of users suddenly report account takeovers, it is a strong indicator that their credentials have been exfiltrated and are being actively used by an attacker. This is often the first real-world sign that a database has been breached and the hashes cracked offline.

Why this answer

Detecting a password database compromise often involves monitoring for unusual database activity or indicators of downstream misuse. A sudden spike in failed login attempts across many accounts (credential stuffing) or an influx of reports from users about account takeovers on unrelated services are classic red flags. These events suggest that the attacker is leveraging stolen hashes to gain unauthorized access elsewhere, making these observations critical for triggering incident response procedures for a potential database breach.

Exam trap

Candidates often look for direct evidence of database access (like SQL logs). However, in many scenarios, the first indication of a database compromise is the downstream impact, such as credential stuffing.

10
MCQmedium

Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?

A.GPUs have higher clock speeds than CPUs
B.GPUs perform massively parallel operations
C.GPUs access system RAM faster than CPUs
D.GPUs use a different instruction set than CPUs
AnswerB

The architecture of a GPU allows it to perform thousands of concurrent calculations. Because each hash attempt is independent of the others, this parallel architecture allows for immense throughput. This turns what would take years on a CPU into a task that takes hours or days on a GPU.

Why this answer

GPUs excel at parallel processing, containing thousands of small cores designed to perform simple mathematical operations simultaneously. Password hashing, particularly MD5 or SHA-1, involves repetitive, independent calculations, which is the perfect workload for a GPU. While a CPU might handle a few operations at once, a GPU can calculate millions of hashes per second.

This speed advantage drastically reduces the time required for brute-force attacks against databases using weak, unsalted, or fast hashing algorithms.

Exam trap

Candidates often assume GPUs are just 'faster CPUs'. The key distinction is that GPUs are designed for massive parallelization, allowing them to perform millions of simple hashing operations simultaneously.

11
MCQmedium

Which of the following describes a 'credential stuffing' attack?

A.Exploiting a buffer overflow to bypass login
B.Using valid credentials from one site to access another
C.Brute-forcing a password using a dictionary file
D.Intercepting credentials via a phishing email
AnswerB

This is the definition of credential stuffing. Because users often reuse passwords, attackers leverage large databases of leaked username/password pairs to gain unauthorized access to accounts on other services, assuming that the credentials will be valid in multiple locations due to human password reuse habits.

Why this answer

Credential stuffing is an automated attack where threat actors use lists of compromised credentials from one breach to attempt logins on unrelated websites. It relies on the common human tendency to reuse passwords across multiple services. Understanding this is vital for incident handlers, as it explains why security alerts for one platform may indicate an account compromise elsewhere.

Mitigation requires enforcing unique passwords and using multi-factor authentication (MFA) to invalidate stolen password utility.

Exam trap

Candidates often confuse credential stuffing with brute-forcing. Brute-forcing guesses a password for one account; credential stuffing uses a list of known credentials to access many different accounts.

12
Multi-Selectmedium

Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?

Select 2 answers
A.Use a unique, random salt for every user
B.Use a global static pepper appended to all hashes
C.Employ a high-cost key derivation function
D.Truncate passwords to 8 characters to save space
E.Store hashes in plain text for performance
AnswersA, C

A unique salt ensures that two users with the same password have different hash outputs. This effectively neutralizes precomputed rainbow table attacks because the attacker would need to generate a new table for every unique salt value, which is computationally impossible for large user databases.

Why this answer

Modern password storage must prioritize computational cost and uniqueness. Using a per-user salt ensures that even identical passwords result in different hashes, preventing rainbow table attacks. Increasing the computational work factor (e.g., iterations) forces attackers to spend more CPU time per guess, making massive brute-force efforts prohibitively expensive.

These controls are foundational to defense-in-depth, protecting user data integrity even when the authentication database is successfully exfiltrated by a threat actor.

Exam trap

Candidates often include 'using a strong encryption algorithm' like AES, which is irrelevant for hashing, as hashing is a one-way function, not encryption, and does not provide protection against offline cracking.

13
Multi-Selectmedium

An incident handler is reviewing password storage mechanisms after a breach. The attacker exfiltrated a file containing password hashes. Which of the following TWO characteristics would make the hashes more resistant to offline cracking? (Choose two.)

Select 2 answers
A.The password policy requires a minimum length of 8 characters with complexity.
B.Each hash includes a unique, random salt value.
C.The hashes are generated using SHA-256 without any salt.
D.The hashes are generated using a slow key derivation function like bcrypt.
E.The hashes are stored in a compressed archive to save space.
AnswersB, D

A unique salt per password ensures that identical passwords produce different hashes, thwarting rainbow table attacks and forcing attackers to crack each hash individually. Salting also prevents attackers from identifying users with the same password. While salting alone does not slow down each hash computation, it eliminates precomputed attacks and increases the overall effort required to crack a large set of hashes.

Why this answer

The two characteristics that make hashes more resistant to offline cracking are the use of a slow key derivation function (like bcrypt) and the inclusion of a unique random salt per hash. A slow KDF increases the time required to compute each hash, while salting prevents the use of precomputed tables and ensures that identical passwords yield different hashes. Together, they significantly raise the cost for an attacker.

Exam trap

The trap here is confusing password policy strength with hash storage security; a strong password policy helps but does not alter the hash's resistance to cracking.

14
MCQmedium

An incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?

A.Buffer overflow in the authentication module
B.SQL injection via the login form
C.Precomputed rainbow table attacks
D.Man-in-the-middle interception
AnswerC

Rainbow tables rely on precomputed hash values for common passwords. Because MD5 is fast and unsalted, attackers can pre-calculate hashes for millions of strings. When a database is stolen, they compare the stolen hashes against the table, revealing plaintext passwords in seconds rather than days of brute forcing.

Why this answer

MD5 is cryptographically broken and prone to collision attacks. Without a salt, identical passwords generate identical hashes, enabling precomputed rainbow table attacks. This allows attackers to instantly crack most of the database by comparing hashes against known lists.

Incident responders must prioritize salting and moving to modern algorithms like Argon2 or bcrypt to ensure that stolen credentials cannot be easily reversed, protecting users from credential stuffing attacks elsewhere.

Exam trap

Candidates often focus on the 'MD5' aspect and assume the answer is 'collision attacks'. While MD5 is weak, the specific risk of unsalted hashes in a database is precomputed rainbow table attacks.

15
MCQeasy

Which of the following is an advantage of using a Key Derivation Function (KDF) like Argon2 over a simple hash like SHA-256?

A.KDFs are faster and improve login performance
B.KDFs are memory-hard and resist GPU cracking
C.KDFs allow for reversible password recovery
D.KDFs require less storage space in the database
AnswerB

Argon2 is a memory-hard KDF, meaning it requires a significant amount of RAM to compute. GPUs have many cores but limited memory per core. This design makes it very difficult for GPUs to parallelize the hashing process, effectively negating their speed advantage and making cracking much slower.

Why this answer

Standard cryptographic hashes like SHA-256 are designed for speed, which is a disadvantage when storing passwords because it allows attackers to test millions of guesses per second. KDFs like Argon2 are specifically designed to be slow and resource-intensive (memory-hard). By forcing the hardware to consume significant memory and time for every single hash calculation, KDFs make large-scale brute-force and dictionary attacks computationally expensive, providing much better security for sensitive credentials.

Exam trap

Candidates often assume KDFs are 'more complex' or 'encrypt the data better'. The primary advantage of KDFs like Argon2 is being 'memory-hard', which forces hardware to use more resources per guess.

16
MCQeasy

A security analyst is examining a Linux system that uses shadow password files. The analyst notices that the password hashes are stored in /etc/shadow and are prefixed with $6$. Which of the following best describes the hashing algorithm used for these passwords?

A.MD5
B.SHA-256
C.bcrypt
D.SHA-512
AnswerD

In Linux shadow files, the prefix $6$ denotes the SHA-512 hashing algorithm. This is a common default on many modern Linux distributions. SHA-512 produces a longer hash and is more resistant to brute-force attacks than MD5 or SHA-256, though it is still a fast hash and should be combined with salting and key stretching.

Why this answer

The $6$ prefix in /etc/shadow explicitly indicates the use of SHA-512 for password hashing. This is part of the crypt(3) library format. While SHA-512 is a cryptographic hash function, it is not inherently slow, so it is often used with a salt to prevent rainbow table attacks.

Understanding these prefixes helps incident handlers quickly identify the hashing algorithm in use.

Exam trap

The trap here is confusing the prefix for SHA-256 ($5$) with that for SHA-512 ($6$), or assuming that a high number means a more secure algorithm like bcrypt.

17
MCQmedium

Which of the following scenarios best demonstrates why multi-factor authentication (MFA) is superior to password-only authentication?

A.It makes passwords faster to type for users
B.It eliminates the need for complex passwords
C.It prevents unauthorized access despite password theft
D.It ensures that the password never expires
AnswerC

MFA creates a requirement for a second, separate piece of evidence. If an attacker steals a password, they still lack the second factor (such as a TOTP app or a hardware token). This makes the stolen password insufficient for the attacker to successfully complete the authentication process.

Why this answer

MFA introduces a secondary requirement that is independent of the password. Even if an attacker obtains the password through phishing, credential stuffing, or a database breach, they cannot gain access without the second factor (like a physical security key or a time-based token). This breaks the single point of failure that exists with password-only systems, rendering stolen credentials useless for unauthorized account access, which is the ultimate goal of the adversary.

Exam trap

Test-takers frequently choose options related to encryption or phishing resistance generally, forgetting that the core superiority of MFA lies specifically in defeating stolen password credentials through orthogonal verification factors.

18
MCQeasy

A junior incident handler is reviewing password storage practices for a legacy application. The application stores passwords as unsalted MD5 hashes. Which of the following best describes the primary risk introduced by the lack of salting?

A.The MD5 algorithm becomes reversible, allowing attackers to decrypt any hash back to the original password using the public MD5 specification.
B.Without a salt, the hash function runs faster, making brute-force attacks more feasible because the attacker can test more candidates per second.
C.The absence of a salt makes the hashes vulnerable to length extension attacks, allowing an attacker to append data and forge valid hashes.
D.Attackers can use precomputed rainbow tables to quickly reverse hashes for common passwords, and identical passwords produce identical hashes, revealing users who share the same password.
AnswerD

This is correct. Without a salt, the same password always produces the same hash, allowing attackers to use precomputed rainbow tables that map hashes to plaintext. This drastically reduces the time to crack common passwords. Additionally, identical hashes in the database indicate that multiple users have chosen the same password, which can be exploited in credential-stuffing attacks. Salting prevents both issues by ensuring unique hashes even for identical passwords and defeating precomputed tables.

Why this answer

The primary risk of unsalted hashes is that attackers can use precomputed rainbow tables to quickly crack common passwords and that identical passwords yield identical hashes, exposing password reuse. Salting addresses both by making each hash unique and defeating precomputation. MD5 remains irreversible, length extension is a separate issue, and salting does not significantly affect hash speed.

Exam trap

The trap here is confusing the role of salting with that of key stretching, assuming that salting slows down brute-force attacks when its main purpose is to prevent precomputation and hash reuse.

Ready to test yourself?

Try a timed practice session using only Understanding Passwords questions.