Courseiva

GPEN · topic practice

Password Attacks and Formats practice questions

This GPEN domain covers how credentials are stored, captured, and cracked during penetration tests. You must recognize hash formats, understand salting and cleartext exposure risks, and select appropriate tools such as Hashcat, John the Ripper, and Mimikatz to recover or reuse credentials.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Password Attacks and Formats

What the exam tests

What to know about Password Attacks and Formats

Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.

Identifying hash types by length and format, such as MD5, NTLM, and bcrypt

Using Hashcat and John the Ripper with correct modes and wordlists

Recognizing cleartext credential exposure in environment variables and config files

Applying salts to defeat rainbow tables and identical-password correlation

Watch out for

Common Password Attacks and Formats exam traps

  • ▸Assuming any 32-character hex string is NTLM when it may be MD5, leading to wrong cracking mode
  • ▸Believing salts make hashes uncrackable rather than just defeating precomputed rainbow tables
  • ▸Forgetting that cleartext credentials in config files or environment variables require no cracking at all

Practice set

Password Attacks and Formats questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. The penetration tester is unable to crack the hash using mode 1800. What is the most likely cause of this failure?

Exhibit

Examine the following output from a password cracking session: 
Hash: $6$rounds=5000$salt$hashstring
Tool: Hashcat -m 1800

Which THREE factors significantly influence the time required to crack a password hash during an offline attack?

Refer to the exhibit. Which attack method is most likely to succeed given this password policy?

Exhibit

Exhibit:
[Policy]
Min_Length = 8
Complexity = Enabled
History_Check = Disabled
Account_Lockout = 3 failed attempts in 30 minutes

Which hashing algorithm is currently considered the most resistant to brute-force attacks due to its design as a memory-hard function?

Refer to the exhibit. What does this hash format indicate about the password for 'user1'?

Exhibit

Exhibit:
user1:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::

A penetration tester has extracted a set of password hashes from a compromised Linux system's `/etc/shadow` file. The hashes are in the format `$6$rounds=5000$salt$hash`. Which TWO of the following statements are true regarding the cracking of these hashes? (Choose two.)

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The hashes are unsalted and the passwords are suspected to be of moderate complexity. Which two techniques would be most effective for rapidly identifying weak passwords while minimizing computational resources? (Choose two.)

A penetration tester extracts a password hash from a database that starts with $2y$10$. Which statement correctly identifies the algorithm and a key characteristic?

You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?

Which TWO of the following password cracking techniques are considered 'offline' attacks?

What is the primary security advantage of utilizing salts in password hashing?

Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

When performing a penetration test, why is it safer to crack hashes offline rather than online?

A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?

A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?

During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?

During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Password Attacks and Formats sessions

Start a Password Attacks and Formats only practice session

Every question in these sessions is drawn from the Password Attacks and Formats domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Password Attacks and Formats?
Be able to identify a captured hash by format, choose the correct Hashcat or John mode, and explain salt benefits. The most important thing is matching hash type to cracking mode; a wrong mode wastes the engagement and fails the question.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Password Attacks and Formats questions in a focused session?
Yes — the session launcher on this page draws every question from the Password Attacks and Formats domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.