GPEN Advanced Password Attacks Practice Question
A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)
⚠ Common exam trap
The trap here is assuming that more computational force (pure brute-force or more threads) is always better, when in fact targeted techniques like rules and masks are far more efficient for typical password patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Utilizing a rule-based attack with a comprehensive rule set like best64.rule
Rule-based attacks and mask attacks are both highly effective for offline NTLM cracking because they intelligently reduce the search space by applying common transformations or adhering to known password policies. Pure brute-force is impractical for long passwords, while options like ignoring usernames or oversubscribing threads do not enhance cracking efficiency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increasing the number of threads to exceed the number of CPU cores
Why it's wrong here
Setting more threads than available CPU cores leads to oversubscription and context switching, which can degrade performance. Hashcat is optimized to use available cores efficiently; exceeding them does not improve cracking speed and may even slow it down due to resource contention.
- ✓
Utilizing a rule-based attack with a comprehensive rule set like best64.rule
Why this is correct
Rule-based attacks apply transformations to dictionary words, significantly expanding the candidate space without requiring a larger wordlist. Using a well-curated rule set like best64.rule can efficiently cover common password mutations, increasing the chances of cracking NTLM hashes while maintaining reasonable processing speed.
- ✗
Using the --username option to ignore usernames during cracking
Why it's wrong here
The --username option in Hashcat tells it to ignore the username field in the hash file, which is useful for parsing but does not affect the cracking efficiency. It neither expands nor reduces the candidate space, so it does not maximize efficiency in an offline attack.
- ✓
Employing a mask attack with a custom character set tailored to the organization's password policy
Why this is correct
A mask attack allows precise definition of password patterns, such as length and character sets. By tailoring the mask to the organization's known password policy (e.g., minimum length, complexity requirements), the tester can drastically reduce the search space and focus computational resources on likely password structures, improving efficiency.
- ✗
Running a pure brute-force attack with all printable ASCII characters up to 12 characters
Why it's wrong here
Pure brute-force over all printable ASCII up to 12 characters is computationally infeasible with current hardware, as the keyspace is enormous. It would take an impractical amount of time, making it an inefficient choice compared to targeted approaches like rules or masks that leverage known patterns.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.