GCIH Attacking Passwords Practice Question
Exhibit
C:\Tools> hashcat -m 1000 -a 0 hashes.txt wordlist.txt [s]tatus [p]ause [b]ypass [c]heckpoint [q]uit => s Status...........: Running Speed.#1.........: 1542.5 kH/s
Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?
⚠ Common exam trap
Candidates often focus on the hash type and forget the 'risk' aspect. They identify NTLM but fail to connect it to the specific threat of lateral movement in Windows domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTLM; risk of credential theft and lateral movement
The exhibit identifies the use of mode 1000, which corresponds to NTLM hashes. The command uses attack mode 0 (straight dictionary attack). This combination is highly effective against Windows networks where NTLM is utilized. The risk is that if the NTLM hash is cracked, the attacker gains the user's secret, allowing for lateral movement or privilege escalation across the entire Windows domain environment using pass-the-hash or direct authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SHA-256; risk of collision attacks
Why it's wrong here
Mode 1000 is specifically defined in hashcat for NTLM hashes, not SHA-256. While SHA-256 is a common hashing algorithm, the command switch -m 1000 directly maps to NTLM, making this option technically incorrect regarding the target hash format.
- ✓
NTLM; risk of credential theft and lateral movement
Why this is correct
Hashcat mode 1000 is standard for NTLM. NTLM is the legacy authentication protocol in Windows, and obtaining the plaintext password or the hash allows an attacker to impersonate the user, move laterally through the network, or escalate privileges within an Active Directory forest.
- ✗
bcrypt; risk of slow brute-force degradation
Why it's wrong here
Bcrypt is represented by mode 3200 in hashcat. Mode 1000 is exclusively for NTLM. Furthermore, bcrypt is designed to be slow, making it resistant to rapid cracking, which contradicts the high speed shown in the exhibit's performance metrics.
- ✗
Kerberos TGT; risk of Golden Ticket generation
Why it's wrong here
Kerberos tickets are typically cracked using modes specific to Kerberos, such as 18200 or 13100. Mode 1000 focuses on NTLM hashes. While Kerberos cracking is a valid threat, the exhibit's command parameters explicitly identify an NTLM-based attack scenario.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.