Courseiva

GPEN Password Attacks and Formats Practice Question

When performing a penetration test, why is it safer to crack hashes offline rather than online?

⚠ Common exam trap

Test-takers sometimes assume online cracking is faster or more direct, ignoring the severe risk of triggering account lockouts and security alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Offline cracking prevents account lockouts.

Offline cracking is performed on the tester's own hardware, which means there is no network traffic generated towards the target system. This prevents the triggering of intrusion detection systems (IDS), account lockout policies, or audit logs that monitor failed authentication attempts. It provides a stealthy way to test password strength without risking operational disruption or alerting the client's defensive security team, which is the primary concern during a professional assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Offline cracking is always faster than online methods.

    Why it's wrong here

    While offline cracking is often faster, it depends on the hardware used. The primary advantage of offline cracking is not speed, but stealth. Speed is a technical benefit, but the operational safety of avoiding detection is the key reason why it is the preferred methodology for ethical penetration testers.

  • ✓

    Offline cracking prevents account lockouts.

    Why this is correct

    Since offline cracking does not involve sending authentication requests to the target, the target's account lockout policy is never triggered. This allows the tester to run millions of attempts per second without any risk of locking out legitimate users, which is essential for maintaining service availability during an engagement.

  • ✗

    Offline cracking allows for the use of more complex passwords.

    Why it's wrong here

    The complexity of the password being tested is determined by the target's policy, not by the cracking method. Both online and offline methods can test passwords of any length or complexity. The method chosen affects the risk of detection and speed, but it does not change the nature of the password.

  • ✗

    Offline cracking is required to obtain the hash from memory.

    Why it's wrong here

    Obtaining the hash (dumping) is a separate step from cracking it. You can dump hashes and still choose to perform an online attack, although that would be illogical. The decision to use offline cracking is based on the desire for speed and stealth, not the process of acquiring the hash itself.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.