GPEN Attacking Password Hashes Practice Question
Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?
⚠ Common exam trap
Candidates mistakenly look for network traffic indicators of offline cracking, forgetting that the actual password guessing computation occurs entirely offline on the attacker's isolated machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Logging access to the LSASS process and SAM hives.
Detecting an offline attack is challenging because the actual computation happens on the attacker's hardware. However, the initial phase—dumping the hashes from memory or the SAM file—requires access to sensitive system files or processes. By monitoring for access to the LSASS process or reading the SAM/SYSTEM registry hives, security teams can identify the signature of a credential dumping attempt, which is the necessary precursor to any offline attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Monitoring for high CPU usage on all workstations.
Why it's wrong here
High CPU usage on a workstation is a generic indicator that can be caused by many benign software processes. It is not an effective way to detect offline cracking because the cracking itself usually happens on the attacker's own external machine, not on the victim's production workstation.
- ✓
Logging access to the LSASS process and SAM hives.
Why this is correct
Credential dumping tools must interact with the LSASS process or read the SAM registry hive to obtain hashes. Monitoring these specific, high-risk actions provides a direct alert for the activity that enables offline cracking, allowing security teams to respond before the hashes are successfully exfiltrated from the network.
- ✗
Scanning for the use of the Hashcat tool on the network.
Why it's wrong here
Attackers can rename tools or use custom scripts that perform the same functions as Hashcat. Relying on simple file-name detection is easily bypassed by renaming the binary, making it an ineffective strategy for detecting professional attackers who are aware of basic signature-based security controls.
- ✗
Monitoring for network traffic to known cracking websites.
Why it's wrong here
Professional attackers do not use websites to perform their cracking operations; they use locally installed, high-performance hardware or cloud-based instances they control. Monitoring web traffic will not identify the exfiltration of credentials or the subsequent offline cracking, as these activities do not require communication with public websites.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.