Courseiva

GCIH · topic practice

Attacking Passwords practice questions

This GCIH domain covers credential theft and offline cracking on Windows and Linux targets. You must recognize Mimikatz modules, LSASS and NTDS.dit dumping, NTLM relay, and hashcat/John usage, then map observed artifacts and sub-status codes to the correct attack technique during incident response.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Attacking Passwords

What the exam tests

What to know about Attacking Passwords

Be able to identify credential-dumping and relay techniques from artifacts, and choose the right cracking or reuse path. The key: distinguish stored NT hashes usable for pass-the-hash from NTLMv2 network responses that must be cracked or relayed.

Mimikatz sekurlsa::logonpasswords extracting plaintext credentials and NTLM hashes from LSASS memory

NTDS.dit extraction from domain controllers and offline cracking with hashcat or John the Ripper

NTLMv2 challenge/response relay via Responder and ntlmrelayx against SMB file servers

Windows logon sub-status codes and event log entries indicating pass-the-hash or brute force

Watch out for

Common Attacking Passwords exam traps

  • ▸Assuming NTLM hashes must be cracked before use; pass-the-hash allows authentication with the hash directly, no plaintext needed.
  • ▸Confusing LM, NTLM, and NTLMv2 challenge/response values; only the NetNTLMv2 response is relayed or cracked offline, not the stored NT hash.
  • ▸Treating LSASS dumping as requiring admin on modern Windows; credential dumping protections and PPL change what access and tooling are needed.

Practice set

Attacking Passwords questions

20 questions · select your answer, then reveal the explanation

An incident responder identifies a compromised workstation using a hash-based NTLM relay attack. Which specific protocol vulnerability is being exploited by the attacker to intercept and pass authentication tokens to a target server without cracking the password?

An organization is auditing its password policies and hash storage. Which TWO of the following practices are considered industry-standard defenses against rapid offline dictionary attacks on hashed credentials?

During an engagement, you observe an attacker attempting to perform a 'Pass-the-Hash' attack. Which THREE of the following conditions or configurations are necessary for the attacker to successfully execute this technique?

An incident responder is analyzing a memory dump from a Windows domain controller and discovers cleartext credentials cached in LSASS.memory. Which utility native to modern Windows operating systems is most commonly abused by attackers to dump this process memory without triggering basic file-activity alerts on disk?

An incident responder is examining a Windows 10 workstation that was compromised via a phishing email. The attacker gained initial access and then extracted cached domain credentials from the system. The responder finds evidence that the attacker used the 'reg save' command to export registry hives and later extracted password hashes offline. Which of the following registry hives would contain the local SAM database and cached domain logons that the attacker likely targeted?

During an incident response engagement at a healthcare provider, you are examining network traffic captured from a compromised Linux web server. You see repeated outbound SSH connection attempts to dozens of internal hosts on port 22, each using the username 'svc_backup' and a different password from a short list. The attempts occur at roughly 50 per second and stop after two minutes. Which password attack technique does this activity most likely represent?

Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?

Exhibit

C:\Tools> hashcat -m 1000 -a 0 hashes.txt wordlist.txt
[s]tatus [p]ause [b]ypass [c]heckpoint [q]uit => s
Status...........: Running
Speed.#1.........: 1542.5 kH/s

Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?

Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?

When analyzing a compromised system, you find evidence of 'Kerberoasting'. What is the primary objective of this attack, and what specific artifact is the attacker attempting to acquire?

Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?

Exhibit

LOG_ENTRY: Event ID 4625 - An account failed to log on.
Account Name: Administrator
Source Network Address: 192.168.1.50
Logon Process: NtLmSsp
Sub Status: 0xC000006A

Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?

When performing a password audit, you identify the use of 'PBKDF2-HMAC-SHA256' for credential storage. What makes this a strong choice compared to basic salted hashes, and how does it specifically hinder offline attacks?

What is the primary vulnerability exploited by the 'Responder' tool during a network-based password attack, and why does it effectively capture sensitive information?

Which of the following password security practices is most effective at preventing the use of 'weak' passwords that are easily identified by dictionary attacks?

Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?

Exhibit

C:\> mimikatz.exe
# privilege::debug
# sekurlsa::logonpasswords

An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the responder needs to prioritize cracking accounts with weak passwords using Hashcat. Which hash mode should be explicitly specified for cracking standard Windows NT LAN Manager (NTLM) password hashes extracted from this database?

An incident handler is reviewing compromised Active Directory domain credentials and notices that an attacker successfully recovered the cleartext password of a service account using an offline cracking tool. Which specific technique did the attacker most likely leverage to target this non-user domain object?

Question 19mediummultiple choice
Review the full subnetting walkthrough →

During an incident response engagement, you capture SMB authentication traffic on a subnet where an attacker has positioned a rogue device. The traffic shows NTLMv2 challenge/response pairs being relayed to a file server that does not enforce SMB signing. Which of the following best describes the security control that would have most directly prevented the relayed authentication from succeeding?

During an incident response engagement at a financial firm, you are reviewing authentication logs on a Windows Server 2019 domain controller. You notice a series of failed logon attempts with Event ID 4625, all originating from a single source IP, using a list of 500 common usernames but only one password attempt per username. The attempts occur over a period of 30 minutes. Which type of password attack is most likely being executed?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Attacking Passwords sessions

Start a Attacking Passwords only practice session

Every question in these sessions is drawn from the Attacking Passwords domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Attacking Passwords?
Be able to identify credential-dumping and relay techniques from artifacts, and choose the right cracking or reuse path. The key: distinguish stored NT hashes usable for pass-the-hash from NTLMv2 network responses that must be cracked or relayed.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Attacking Passwords questions in a focused session?
Yes — the session launcher on this page draws every question from the Attacking Passwords domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.