GPEN · domain
Advanced Password Attacks
This domain covers credential theft and cracking on Windows/AD networks: LLMNR/NBT-NS poisoning to capture Net-NTLMv2, Kerberos pre-auth attacks (AS-REP roasting, Kerberoasting), and offline hash recovery with Hashcat/John. GPEN tests your ability to choose the right capture technique, hash mode, and post-capture step under time pressure.
Focused practice
Practice Advanced Password Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Advanced Password Attacks
You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.
Responder LLMNR/NBT-NS poisoning to capture Net-NTLMv2 hashes on internal networks
Hashcat modes for Net-NTLMv2 (5600) and Kerberos AS-REP (18200) offline cracking
Kerberos AS-REP roasting against accounts without pre-authentication enabled
Kerberoasting via SPN enumeration and TGS-REP extraction for offline cracking
Watch out for
Common Advanced Password Attacks exam traps
- ▸Using the wrong Hashcat mode for Net-NTLMv2 (e.g., 1000 instead of 5600), causing failed or invalid cracking attempts.
- ▸Confusing AS-REP roasting (no pre-auth) with Kerberoasting (requires SPN and valid credentials), leading to wrong tooling and targets.
- ▸Assuming captured Net-NTLMv2 can be relayed or cracked quickly; weak wordlists and no rules often yield no plaintext.
Question index
All Advanced Password Attacks questions (26)
Click any question to see the full explanation, or start a practice session above.
A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?
Easy2When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)
Hard3A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?
Easy4During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)
Hard5A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?
Medium6During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?
Medium7What is the primary risk associated with storing credentials in plain text within scripts or configuration files?
Medium8During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?
Medium9During a penetration test, an operator captures a network authentication attempt using the NTLMv2 protocol. The operator wants to crack the captured challenge-response offline using Hashcat. Which hash mode should the operator select to correctly process the captured NetNTLMv2 hash?
Hard10Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?
Medium11Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?
Medium12During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?
Hard13A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)
Medium14During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?
Medium15A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)
Medium16Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?
Medium17Which THREE conditions must be met for a successful AS-REP Roasting attack?
Hard18During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?
Medium19During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?
Medium20During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?
Medium21During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a workstation. You attempt to crack it offline using Hashcat, but after several hours with a large wordlist and rules, the hash remains uncracked. Which factor most directly determines the feasibility of cracking this hash?
Hard22A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?
Hard23In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?
Medium24A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)
Medium25A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
Medium26A penetration tester has obtained a single NT hash for a domain user account during an internal engagement. The tester wants to authenticate to a remote Windows 10 workstation as that user without knowing the plaintext password. Which tool is designed to perform this authentication using only the NT hash?
MediumOther domains
All GPEN exam domains
Frequently asked questions
- What does the Advanced Password Attacks domain cover on the GPEN exam?
- You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.
- How many questions are in this domain?
- This page lists all 26 Advanced Password Attacks questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Advanced Password Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.