Courseiva

GPEN Attacking Password Hashes Practice Question

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

⚠ Common exam trap

Candidates often assume that if a password policy is sufficiently strict, the underlying hashing algorithm becomes irrelevant. They fail to realize that offline attacks bypass policy enforcement entirely by targeting stored hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Weak algorithms allow rapid recovery of passwords once a breach occurs.

Even with a strong password policy, an organization remains vulnerable if the hashing algorithm is cryptographically broken or lacks proper salting. A weak algorithm like MD5 or NTLM allows attackers to crack even complex passwords almost instantaneously using modern hardware. Evaluating the hashing implementation ensures that the organization is protected against offline attacks, providing a necessary layer of defense that policies alone cannot guarantee if the underlying data storage mechanism is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password policies are easily bypassed by users sharing credentials.

    Why it's wrong here

    While credential sharing is a risk, it is unrelated to the cryptographic strength of the password storage mechanism. Even if users shared complex passwords, they would remain vulnerable if the underlying hashing algorithm was outdated, such as MD5, which can be computed in microseconds by modern cracking tools.

  • ✓

    Weak algorithms allow rapid recovery of passwords once a breach occurs.

    Why this is correct

    If the hashing algorithm is weak or lacks a salt, an attacker can crack the database in bulk regardless of the complexity enforced by the policy. A strong hashing algorithm acts as the final line of defense, rendering stolen hash files useless even when the database is fully compromised.

  • ✗

    Passwords are always transmitted in plain text over the network.

    Why it's wrong here

    Passwords should not be transmitted in plain text if secure protocols like HTTPS are used. This statement is a false premise; assuming all traffic is insecure ignores modern transport security standards, which are independent of how passwords are stored in the back-end database after they are hashed.

  • ✗

    The password policy is only effective for local accounts.

    Why it's wrong here

    Password policies can be enforced for both local and domain accounts through Group Policy or identity management systems. The assertion that policies are ineffective for non-local accounts is incorrect and does not justify prioritizing the evaluation of hashing algorithms over the assessment of organizational security policies.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.