GPEN Advanced Password Attacks Practice Question
During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?
⚠ Common exam trap
Watch out — candidates often confuse cached domain credentials with NTLM hashes stored in the SAM database, leading to the selection of an incorrect Hashcat mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat mode 2100 (Domain Cached Credentials 2, MS Cache 2)
Cached domain credentials are stored as MSCache v2 hashes in the SECURITY registry hive. Hashcat mode 2100 is purpose-built to crack these hashes offline. Other modes target different hash types such as NTLM, LM, or NetNTLMv2, which are not applicable here. Using the correct mode ensures efficient and successful cracking of the cached credential.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashcat mode 1000 (NTLM)
Why it's wrong here
Mode 1000 targets raw NTLM hashes, such as those found in the SAM database or NTDS.dit. The cached domain credential is stored as an MSCache hash, which uses a different algorithm and format. Using mode 1000 against an MSCache hash will fail because the hash structure and computation do not match, so it is not the correct choice here.
- ✗
Hashcat mode 5500 (NetNTLMv2)
Why it's wrong here
Mode 5500 is used for NetNTLMv2 challenge-response hashes captured from network authentication, not for cached domain credentials stored locally. NetNTLMv2 hashes require a challenge and response pair, which is not present in the registry cache. Therefore, mode 5500 is unsuitable for cracking the cached domain hash described in the scenario.
- ✗
Hashcat mode 3000 (LM)
Why it's wrong here
Mode 3000 targets LM hashes, which are legacy and not used for cached domain credentials. LM hashes are stored in the SAM database on older systems and are easily cracked due to weak hashing. Applying mode 3000 to an MSCache hash would not work because the hash formats are incompatible, making it an incorrect choice for this scenario.
- ✓
Hashcat mode 2100 (Domain Cached Credentials 2, MS Cache 2)
Why this is correct
MSCache v2 hashes are stored in the registry under SECURITY\Cache and are used for offline domain logon. Hashcat mode 2100 is specifically designed to crack these Domain Cached Credentials 2 hashes. Since the scenario involves a cached domain credential from a workstation, mode 2100 is the correct mode to use for offline cracking.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.