GPEN Password Attacks and Formats Practice Question
A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?
⚠ Common exam trap
Watch out — candidates often confuse MD5 with NTLM because both produce 32-character hashes, but context and known hash examples help differentiate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MD5, and Hashcat can be used with mode 0.
The hash is 32 characters long, which is the length of an MD5 hash. Hashcat mode 0 is used for raw MD5 hashes. This is a straightforward identification task. The hash `5f4dcc3b5aa765d61d8327deb882cf99` is a common example (MD5 of 'password'), but the key is recognizing the format. A penetration tester should use this knowledge to select the correct cracking mode and proceed with offline cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
MD5, and Hashcat can be used with mode 0.
Why this is correct
The hash is 32 hexadecimal characters, characteristic of MD5. Hashcat mode 0 is specifically for raw MD5 hashes. This is a common scenario in penetration testing when web applications use MD5 without salts. The tester can use Hashcat with a wordlist or rules to crack it. The hash `5f4dcc3b5aa765d61d8327deb882cf99` is the MD5 of 'password', a well-known example.
- ✗
SHA-256, and Hashcat can be used with mode 1400.
Why it's wrong here
SHA-256 hashes are 64 hexadecimal characters, not 32. Mode 1400 is for SHA-256. The given hash is too short for SHA-256. This option misidentifies the hash type. Using mode 1400 would be incorrect and fail to crack the hash. The tester must match the hash length to the correct algorithm and mode.
- ✗
SHA-1, and Hashcat can be used with mode 100.
Why it's wrong here
SHA-1 hashes are 40 hexadecimal characters long, not 32. Mode 100 in Hashcat is for SHA-1. The given hash length indicates MD5, not SHA-1. Using the wrong mode would result in failure to crack the hash. The tester must correctly identify the hash type by its length and format to select the appropriate cracking mode.
- ✗
NTLM, and Hashcat can be used with mode 1000.
Why it's wrong here
NTLM hashes are 32 hexadecimal characters, same as MD5, but they are used in Windows environments. The hash `5f4dcc3b5aa765d61d8327deb882cf99` is actually the MD5 of 'password', not an NTLM hash. However, without context, it's ambiguous; but NTLM is not typically found in web application databases. The tester should consider the source and hash format to distinguish between MD5 and NTLM.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.