Courseiva

GPEN · domain

Attacking Password Hashes

This domain covers extracting and cracking Windows credential material: NTLM and NTLMv2 hashes, LSASS and SAM dumps, and offline attacks with Hashcat and John the Ripper. GPEN questions present a capture or dump scenario and ask which technique, tool, or cracking mode is correct for recovering plaintext or abusing the hash.

23 questions4 easy12 medium7 hard

Focused practice

Practice Attacking Password Hashes questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Attacking Password Hashes

Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.

Distinguishing NTLM hash cracking from NTLMv2 challenge-response cracking and their Hashcat modes

Using Mimikatz or similar tooling to dump LSASS and extract credential material

Extracting and parsing SAM/SYSTEM hives with secretsdump, pwdump, or samdump2

Choosing offline brute-force, dictionary, or rule-based attacks against captured hashes

Watch out for

Common Attacking Password Hashes exam traps

  • ▸Treating NTLMv2 challenge-response pairs as crackable NTLM hashes; they require a different Hashcat mode and network capture context
  • ▸Assuming LSASS dumping always yields plaintext; it may only return NTLM hashes needing cracking or pass-the-hash
  • ▸Confusing SAM extraction tools with cracking tools, or forgetting the SYSTEM hive is needed to decrypt SAM hashes

Question index

All Attacking Password Hashes questions (23)

Click any question to see the full explanation, or start a practice session above.

1

During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?

Easy
2

Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?

Hard
3

Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?

Hard
4

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

Medium
5

During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?

Medium
6

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)

Hard
7

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

Hard
8

A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?

Easy
9

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

Easy
10

During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?

Hard
11

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

Medium
12

A penetration tester captures a NetNTLMv2 hash from a network segment using Responder. The tester wants to crack this hash using Hashcat. Which Hashcat mode should be used?

Hard
13

A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?

Medium
14

A penetration tester has obtained a set of Linux shadow file hashes. The hashes begin with $6$ and the tester intends to perform an offline brute-force attack using Hashcat. Which mode should the tester select to ensure Hashcat correctly interprets these hashes?

Medium
15

You are conducting an internal penetration test and have obtained a set of NTLM hashes from a compromised server. You want to crack them using Hashcat on a dedicated GPU rig. Which hash mode should you use?

Medium
16

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Hard
17

During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?

Easy
18

A penetration tester is performing an offline attack against a Kerberos TGS-REP hash obtained via Kerberoasting. Which of the following Hashcat modes should be used?

Medium
19

Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?

Medium
20

During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?

Medium
21

During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?

Medium
22

Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?

Medium
23

During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?

Medium

Frequently asked questions

What does the Attacking Password Hashes domain cover on the GPEN exam?
Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.
How many questions are in this domain?
This page lists all 23 Attacking Password Hashes questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Attacking Password Hashes questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN attacking password hashes Practice Questions