GPEN · domain
Password Attacks and Formats
This GPEN domain covers how credentials are stored, captured, and cracked during penetration tests. You must recognize hash formats, understand salting and cleartext exposure risks, and select appropriate tools such as Hashcat, John the Ripper, and Mimikatz to recover or reuse credentials.
Focused practice
Practice Password Attacks and Formats questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Password Attacks and Formats
Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
Identifying hash types by length and format, such as MD5, NTLM, and bcrypt
Using Hashcat and John the Ripper with correct modes and wordlists
Recognizing cleartext credential exposure in environment variables and config files
Applying salts to defeat rainbow tables and identical-password correlation
Watch out for
Common Password Attacks and Formats exam traps
- ▸Assuming any 32-character hex string is NTLM when it may be MD5, leading to wrong cracking mode
- ▸Believing salts make hashes uncrackable rather than just defeating precomputed rainbow tables
- ▸Forgetting that cleartext credentials in config files or environment variables require no cracking at all
Question index
All Password Attacks and Formats questions (19)
Click any question to see the full explanation, or start a practice session above.
A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?
Easy2When performing a penetration test, why is it safer to crack hashes offline rather than online?
Medium3During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?
Easy4Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?
Medium5During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?
Medium6Which TWO of the following password cracking techniques are considered 'offline' attacks?
Medium7During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?
Hard8During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?
Medium9A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?
Medium10What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?
Medium11A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?
Medium12What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
Medium13Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?
Medium14A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)
Medium15What is the primary security advantage of utilizing salts in password hashing?
Easy16A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?
Medium17A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?
Easy18You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?
Medium19A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?
MediumOther domains
All GPEN exam domains
Frequently asked questions
- What does the Password Attacks and Formats domain cover on the GPEN exam?
- Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
- How many questions are in this domain?
- This page lists all 19 Password Attacks and Formats questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Password Attacks and Formats questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.