Courseiva
Attacking Password Hashes →mediumMultiple Choice

GPEN Attacking Password Hashes Practice Question

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

⚠ Common exam trap

Candidates often select manual analysis or basic dictionary attacks alone, overlooking the efficiency of hybrid wordlist and mask attacks executed via optimized GPU tools like Hashcat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run Hashcat with a combination of wordlists and mask attacks.

Once NTLM hashes are acquired, the most efficient method to recover the password is using an optimized GPU-based cracking tool like Hashcat. By employing a hybrid attack strategy—starting with a dictionary list supplemented by mask-based brute forcing—the tester can maximize the likelihood of recovering passwords that follow common corporate complexity patterns. This is significantly faster than manual analysis and allows for rapid testing against high-value target accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the hashes to perform a Pass-the-Hash attack on every server.

    Why it's wrong here

    Pass-the-Hash is an authentication technique, not a cracking technique. It is useful for lateral movement but does not reveal the plaintext password. If the goal specifically asks for the password recovery, Pass-the-Hash fails to satisfy the requirement as it only grants access without revealing the credentials.

  • ✗

    Submit the hashes to an online cloud-based cracking service.

    Why it's wrong here

    Submitting sensitive organizational credentials to a third-party cloud service is a severe violation of professional ethics and data privacy rules. A penetration tester must maintain control over client data and should never expose credentials to external, untrusted environments during the engagement process.

  • ✓

    Run Hashcat with a combination of wordlists and mask attacks.

    Why this is correct

    Hashcat is the industry standard for offline cracking. By using dictionary files for common passwords and mask attacks for complexity patterns, a tester can efficiently find the password. This method is highly scalable and leverages GPU hardware to test millions of variations per second.

  • ✗

    Reverse the MD4 algorithm to recover the original string.

    Why it's wrong here

    Hashing is a one-way cryptographic function, and it is mathematically impossible to 'reverse' the algorithm to recover the original input. Any attempt to reverse the MD4 function mathematically will result in failure, as the process is designed to be irreversible, unlike standard encryption or encoding.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.