Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

Exhibit

C:\Tools> hashcat -m 1000 -a 0 hashes.txt wordlist.txt
[s]tatus [p]ause [b]ypass [c]heckpoint [q]uit => s
Status...........: Running
Speed.#1.........: 1542.5 kH/s

Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?

⚠ Common exam trap

Candidates often focus on the hash type and forget the 'risk' aspect. They identify NTLM but fail to connect it to the specific threat of lateral movement in Windows domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTLM; risk of credential theft and lateral movement

The exhibit identifies the use of mode 1000, which corresponds to NTLM hashes. The command uses attack mode 0 (straight dictionary attack). This combination is highly effective against Windows networks where NTLM is utilized. The risk is that if the NTLM hash is cracked, the attacker gains the user's secret, allowing for lateral movement or privilege escalation across the entire Windows domain environment using pass-the-hash or direct authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-256; risk of collision attacks

    Why it's wrong here

    Mode 1000 is specifically defined in hashcat for NTLM hashes, not SHA-256. While SHA-256 is a common hashing algorithm, the command switch -m 1000 directly maps to NTLM, making this option technically incorrect regarding the target hash format.

  • ✓

    NTLM; risk of credential theft and lateral movement

    Why this is correct

    Hashcat mode 1000 is standard for NTLM. NTLM is the legacy authentication protocol in Windows, and obtaining the plaintext password or the hash allows an attacker to impersonate the user, move laterally through the network, or escalate privileges within an Active Directory forest.

  • ✗

    bcrypt; risk of slow brute-force degradation

    Why it's wrong here

    Bcrypt is represented by mode 3200 in hashcat. Mode 1000 is exclusively for NTLM. Furthermore, bcrypt is designed to be slow, making it resistant to rapid cracking, which contradicts the high speed shown in the exhibit's performance metrics.

  • ✗

    Kerberos TGT; risk of Golden Ticket generation

    Why it's wrong here

    Kerberos tickets are typically cracked using modes specific to Kerberos, such as 18200 or 13100. Mode 1000 focuses on NTLM hashes. While Kerberos cracking is a valid threat, the exhibit's command parameters explicitly identify an NTLM-based attack scenario.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.