GPEN Advanced Password Attacks Practice Question
A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
⚠ Common exam trap
Many candidates mistakenly select Mimikatz for this specific offline task. While Mimikatz is powerful, it is primarily an in-memory tool, whereas secretsdump.py is the dedicated utility for parsing offline files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
secretsdump.py
Impacket's secretsdump.py is the industry standard for parsing NTDS.dit files and SYSTEM hives to extract domain credentials. It leverages the boot key stored in the SYSTEM hive to decrypt the encrypted hashes within the NTDS.dit database. Understanding this process is critical for penetration testers because it represents the most common method of achieving domain-wide compromise after gaining the necessary domain controller files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat
Why it's wrong here
Hashcat is a high-performance password recovery tool designed for cracking hashes once they are already obtained. It cannot directly extract hashes from a raw NTDS.dit database file. It requires the hashes to be in a specific format like NTLM or NetNTLMv2 before it can begin processing them.
- ✗
Mimikatz
Why it's wrong here
Mimikatz is excellent for extracting credentials from memory on a live system using techniques like sekurlsa::logonpasswords. While it can perform offline NTDS.dit parsing, it is primarily used for volatile memory extraction, whereas secretsdump.py is purpose-built for the systematic extraction of all database entries offline.
- ✓
secretsdump.py
Why this is correct
Secretsdump.py is the definitive tool within the Impacket suite for performing local or remote secret extraction. By providing the NTDS.dit and SYSTEM hive files, it decrypts the database, allowing the tester to retrieve NTLM hashes for every user in the domain, which is essential for subsequent offline cracking attempts.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is a versatile password cracking tool that supports many hash types. Similar to Hashcat, it operates on hashes that have already been extracted. It does not possess the capability to parse the proprietary Microsoft JET database format used by the NTDS.dit file structure.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.