Courseiva

GPEN · domain

Advanced Password Attacks

This domain covers credential theft and cracking on Windows/AD networks: LLMNR/NBT-NS poisoning to capture Net-NTLMv2, Kerberos pre-auth attacks (AS-REP roasting, Kerberoasting), and offline hash recovery with Hashcat/John. GPEN tests your ability to choose the right capture technique, hash mode, and post-capture step under time pressure.

26 questions2 easy17 medium7 hard

Focused practice

Practice Advanced Password Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Advanced Password Attacks

You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.

Responder LLMNR/NBT-NS poisoning to capture Net-NTLMv2 hashes on internal networks

Hashcat modes for Net-NTLMv2 (5600) and Kerberos AS-REP (18200) offline cracking

Kerberos AS-REP roasting against accounts without pre-authentication enabled

Kerberoasting via SPN enumeration and TGS-REP extraction for offline cracking

Watch out for

Common Advanced Password Attacks exam traps

  • ▸Using the wrong Hashcat mode for Net-NTLMv2 (e.g., 1000 instead of 5600), causing failed or invalid cracking attempts.
  • ▸Confusing AS-REP roasting (no pre-auth) with Kerberoasting (requires SPN and valid credentials), leading to wrong tooling and targets.
  • ▸Assuming captured Net-NTLMv2 can be relayed or cracked quickly; weak wordlists and no rules often yield no plaintext.

Question index

All Advanced Password Attacks questions (26)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?

Easy
2

When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)

Hard
3

A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?

Easy
4

During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)

Hard
5

A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?

Medium
6

During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?

Medium
7

What is the primary risk associated with storing credentials in plain text within scripts or configuration files?

Medium
8

During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?

Medium
9

During a penetration test, an operator captures a network authentication attempt using the NTLMv2 protocol. The operator wants to crack the captured challenge-response offline using Hashcat. Which hash mode should the operator select to correctly process the captured NetNTLMv2 hash?

Hard
10

Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?

Medium
11

Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?

Medium
12

During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?

Hard
13

A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)

Medium
14

During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?

Medium
15

A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)

Medium
16

Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?

Medium
17

Which THREE conditions must be met for a successful AS-REP Roasting attack?

Hard
18

During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?

Medium
19

During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?

Medium
20

During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?

Medium
21

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a workstation. You attempt to crack it offline using Hashcat, but after several hours with a large wordlist and rules, the hash remains uncracked. Which factor most directly determines the feasibility of cracking this hash?

Hard
22

A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?

Hard
23

In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?

Medium
24

A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)

Medium
25

A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?

Medium
26

A penetration tester has obtained a single NT hash for a domain user account during an internal engagement. The tester wants to authenticate to a remote Windows 10 workstation as that user without knowing the plaintext password. Which tool is designed to perform this authentication using only the NT hash?

Medium

Frequently asked questions

What does the Advanced Password Attacks domain cover on the GPEN exam?
You must capture the right hash type, select the correct Hashcat mode, and crack offline. The single most important thing: know that AS-REP roasting targets accounts without Kerberos pre-authentication, and use mode 18200 to recover the password.
How many questions are in this domain?
This page lists all 26 Advanced Password Attacks questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Advanced Password Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN advanced password attacks Practice Questions