GPEN Advanced Password Attacks Practice Question
During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?
⚠ Common exam trap
Candidates often assume that failing to crack a hash with a default wordlist means the hash is entirely uncrackable or improperly captured, leading them to abandon offline attempts prematurely instead of applying rules or combinator attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply rule-based attack modes or hybrid mask attacks in Hashcat to mutate base wordlist entries with common character substitutions, appending numbers, and special symbols.
NTLMv2 hashes utilize a challenge-response mechanism that cannot be reversed directly, requiring offline brute-forcing or rule-based attacks against the captured challenge and response. Because standard wordlists often fail against complex alphanumeric passwords, applying dynamic rule sets or combining masks significantly expands the search space to cover permutations users typically create to satisfy strict corporate password policies during assessments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Re-capture the hash using Kerberoasting to obtain a valid Ticket Granting Service ticket for a service principal name instead of relying on the LLMNR response.
Why it's wrong here
Kerberoasting yields a Kerberos TGS ticket encrypted with the service account's key, not the user's net-NTLMv2 response, so it cannot recover the captured user's plaintext. It is tempting because Kerberoasting genuinely extracts crackable service account material, which is correct when targeting service accounts with SPNs rather than a poisoned LLMNR response.
- ✗
Convert the net-NTLMv2 hash format directly into an MD5 hash format using a custom script so that standard rainbow tables can instantly identify the plaintext password string.
Why it's wrong here
Net-NTLMv2 is a challenge-response value, not a stored hash; converting it to MD5 is cryptographically meaningless because no rainbow table maps that transformation. It is tempting because rainbow tables genuinely accelerate cracking of unsalted MD5 password hashes, which is the right approach when the captured artefact is an actual MD5 digest.
- ✓
Apply rule-based attack modes or hybrid mask attacks in Hashcat to mutate base wordlist entries with common character substitutions, appending numbers, and special symbols.
Why this is correct
NTLMv2 hashing defeats plain wordlist matching because the hash incorporates challenge-response data. Rule-based and hybrid mask modes mutate rockyou entries with substitutions, appended digits, and symbols, approximating the complexity-compliant passwords that a raw dictionary attack cannot reach.
- ✗
Downgrade the captured authentication traffic by forcing the domain controller to negotiate LM hashing during the next SMB session establishment phase to simplify cracking.
Why it's wrong here
LM hashing cannot be negotiated on demand; modern Windows domains disable or refuse LM by policy, and the captured net-NTLMv2 response is already fixed. It is tempting because LM's weak, truncated keys genuinely crack quickly, which would be correct only where legacy LM authentication is still enabled and captured.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.