Courseiva

GPEN · topic practice

Attacking Password Hashes practice questions

This domain covers extracting and cracking Windows credential material: NTLM and NTLMv2 hashes, LSASS and SAM dumps, and offline attacks with Hashcat and John the Ripper. GPEN questions present a capture or dump scenario and ask which technique, tool, or cracking mode is correct for recovering plaintext or abusing the hash.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Attacking Password Hashes

What the exam tests

What to know about Attacking Password Hashes

Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.

Distinguishing NTLM hash cracking from NTLMv2 challenge-response cracking and their Hashcat modes

Using Mimikatz or similar tooling to dump LSASS and extract credential material

Extracting and parsing SAM/SYSTEM hives with secretsdump, pwdump, or samdump2

Choosing offline brute-force, dictionary, or rule-based attacks against captured hashes

Watch out for

Common Attacking Password Hashes exam traps

  • ▸Treating NTLMv2 challenge-response pairs as crackable NTLM hashes; they require a different Hashcat mode and network capture context
  • ▸Assuming LSASS dumping always yields plaintext; it may only return NTLM hashes needing cracking or pass-the-hash
  • ▸Confusing SAM extraction tools with cracking tools, or forgetting the SYSTEM hive is needed to decrypt SAM hashes

Practice set

Attacking Password Hashes questions

20 questions · select your answer, then reveal the explanation

A penetration tester has successfully obtained a SAM database file. Which technique is most effective for extracting NTLM hashes while avoiding detection by traditional file-integrity monitoring systems that flag direct reads of the active SYSTEM hive?

Refer to the exhibit. Given the Hashcat output, what is the most significant bottleneck affecting the efficiency of the NTLM password cracking attack?

Exhibit

C:\Tools> hashcat -m 1000 hashes.txt rockyou.txt

[s]tatus [p]ause [r]esume [b]ypass [c]heckpoint [q]uit => s
Status...........: Running
Speed.#1.........: 12.5 MH/s
Recovered........: 0/1500 (0.00%)
Progress.........: 12500000/400000000 (3.12%)
HWMon.Dev.#1.....: Temp: 78C Fan: 80% Util: 99%

Which TWO of the following factors most significantly increase the time required to crack a password hash using offline brute-force attacks?

A tester is performing an offline attack against a Kerberos TGT (Ticket Granting Ticket) hash. What is this specific attack vector commonly known as in a Windows Active Directory environment?

Which THREE of the following are common indicators that a Windows environment is vulnerable to credential extraction from the LSASS process?

You have successfully obtained a copy of the NTDS.dit database and the SYSTEM registry hive during a domain controller compromise. Which TWO tools can you use offline to extract the password hashes from these files without relying on living-off-the-land binaries on a live system? (Choose TWO)

A penetration tester extracts a Kerberos 5 TGS-REP hash (etype 23) from a service account and attempts to crack it offline using Hashcat. The tester uses mode 13100. After running Hashcat, the tester notices that the hash is not being cracked despite using a large wordlist. Which of the following is the most likely reason for the failure?

You have extracted a set of NTLM hashes from a Windows domain controller and want to crack them using Hashcat. Which TWO of the following are effective strategies to increase cracking success? (Choose two.)

A penetration tester has obtained a set of NTLM hashes from a compromised Windows system and wants to crack them using a rule-based dictionary attack. Which TWO of the following Hashcat options are essential to perform this attack effectively? (Choose two.)

A penetration tester extracts a local user account's NT hash from a Windows workstation and wants to use it to authenticate to other workstations in the same domain. The domain has NTLM authentication enabled. Which of the following conditions is necessary for the Pass-the-Hash attack to succeed?

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

Exhibit

C:\> mimikatz.exe

mimikatz # privilege::debug
Privilege '20' OK

mimikatz # sekurlsa::logonpasswords

[...]
Authentication Id : 0 ; 123456 (00000000:0001e240)
Session           : Interactive from 1
User Name         : admin
Domain            : CORP
Logon Server      : DC01
LM NTLM           : a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6

Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?

Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?

Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?

During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?

During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?

During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Attacking Password Hashes sessions

Start a Attacking Password Hashes only practice session

Every question in these sessions is drawn from the Attacking Password Hashes domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Attacking Password Hashes?
Be able to identify the hash type from a capture or dump, select the correct extraction tool and Hashcat mode, and run an offline cracking attack. The key is matching hash format to attack method rather than assuming every credential yields plaintext.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Attacking Password Hashes questions in a focused session?
Yes — the session launcher on this page draws every question from the Attacking Password Hashes domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.