Courseiva

GPEN Password Attacks and Formats Practice Question

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

⚠ Common exam trap

The trap here is assuming that rainbow tables are always effective for unsalted hashes, but their size and lookup overhead make them less practical than rule-based GPU cracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Leveraging GPU acceleration with Hashcat

Rule-based attacks and GPU acceleration are both highly effective for offline cracking of NTLM hashes. Rule-based attacks expand the wordlist with common transformations, covering many user-chosen passwords. GPU acceleration with Hashcat maximizes computational speed, allowing millions of guesses per second. Together, they significantly improve the success rate. Other options like rainbow tables or online attacks are either impractical or inefficient in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Leveraging GPU acceleration with Hashcat

    Why this is correct

    GPU acceleration dramatically increases the number of hash computations per second compared to CPU-only cracking. Hashcat is optimized for GPU usage and can crack NTLM hashes at very high rates. This makes it a highly effective technique for offline attacks, reducing the time required to test large numbers of password candidates.

  • ✗

    Conducting an online brute-force attack against the domain controller

    Why it's wrong here

    Online brute-force attacks are slow, noisy, and likely to trigger account lockout policies. They are not effective for cracking a large set of hashes because each attempt requires a network round-trip and authentication. Offline cracking is preferred when hashes are already obtained, as it avoids detection and lockouts.

  • ✓

    Using a rule-based attack with a comprehensive wordlist

    Why this is correct

    Rule-based attacks apply transformations like appending numbers or substituting characters to each word in a wordlist. This mimics common password creation patterns and significantly increases the chances of cracking NTLM hashes, especially when users follow predictable complexity requirements. It is a standard and effective technique in offline cracking.

  • ✗

    Performing a rainbow table attack using precomputed tables for NTLM

    Why it's wrong here

    Rainbow tables for NTLM are large and less effective because NTLM hashes are unsalted but the keyspace is vast. Precomputed tables can be defeated by salting, but NTLM lacks salts. However, the storage and lookup requirements are impractical for complex passwords, and modern cracking with GPUs often outperforms rainbow tables. Thus, it is not the most effective technique here.

  • ✗

    Using a dictionary attack with a list of common passwords only

    Why it's wrong here

    A plain dictionary attack without rules is limited to the exact words in the list. Many passwords include variations like capitalized first letters or appended digits, so this approach misses a significant portion. While it is fast, it is less effective than rule-based attacks for complex passwords. It should be combined with other techniques for better results.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.