Courseiva

GPEN · domain

Password Attacks and Formats

This GPEN domain covers how credentials are stored, captured, and cracked during penetration tests. You must recognize hash formats, understand salting and cleartext exposure risks, and select appropriate tools such as Hashcat, John the Ripper, and Mimikatz to recover or reuse credentials.

19 questions4 easy14 medium1 hard

Focused practice

Practice Password Attacks and Formats questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Password Attacks and Formats

Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.

Identifying hash types by length and format, such as MD5, NTLM, and bcrypt

Using Hashcat and John the Ripper with correct modes and wordlists

Recognizing cleartext credential exposure in environment variables and config files

Applying salts to defeat rainbow tables and identical-password correlation

Watch out for

Common Password Attacks and Formats exam traps

  • ▸Assuming any 32-character hex string is NTLM when it may be MD5, leading to wrong cracking mode
  • ▸Believing salts make hashes uncrackable rather than just defeating precomputed rainbow tables
  • ▸Forgetting that cleartext credentials in config files or environment variables require no cracking at all

Question index

All Password Attacks and Formats questions (19)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?

Easy
2

When performing a penetration test, why is it safer to crack hashes offline rather than online?

Medium
3

During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?

Easy
4

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

Medium
5

During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?

Medium
6

Which TWO of the following password cracking techniques are considered 'offline' attacks?

Medium
7

During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?

Hard
8

During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?

Medium
9

A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?

Medium
10

What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?

Medium
11

A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?

Medium
12

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

Medium
13

Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?

Medium
14

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Medium
15

What is the primary security advantage of utilizing salts in password hashing?

Easy
16

A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?

Medium
17

A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?

Easy
18

You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?

Medium
19

A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?

Medium

Frequently asked questions

What does the Password Attacks and Formats domain cover on the GPEN exam?
Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
How many questions are in this domain?
This page lists all 19 Password Attacks and Formats questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Password Attacks and Formats questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN password attacks and formats Practice Questions