PEN-200 · domain
Password Attacks
This domain covers credential capture and offline cracking across Windows and Linux targets: NetNTLMv2 challenge-response, AS-REP Roasting, Kerberoasting, /etc/shadow hashes, and encoded credentials in cookies. PEN-200 tests whether you can identify the hash or encoding format, choose the correct tool and mode, and recover plaintext to pivot or escalate.
Focused practice
Practice Password Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Password Attacks
Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
Recognizing hash formats such as NetNTLMv2, AS-REP, Kerberoast, and Linux crypt(3) identifiers like $6$
Selecting Hashcat modes and John the Ripper formats for each captured hash type
Using Responder, Impacket, and Mimikatz to capture or request credentials in Active Directory
Identifying weak encoding like base64 in cookies versus actual encryption or hashing
Watch out for
Common Password Attacks exam traps
- ▸Treating base64-encoded credentials as secure encryption instead of trivially reversible encoding.
- ▸Using the wrong Hashcat mode or John format, so cracking fails despite a valid hash and wordlist.
- ▸Confusing AS-REP Roasting with Kerberoasting; AS-REP requires no Kerberos pre-authentication on the target account.
Question index
All Password Attacks questions (23)
Click any question to see the full explanation, or start a practice session above.
When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?
Easy2You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?
Medium3During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?
Medium4Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?
Hard5You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?
Easy6During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?
Medium7Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?
Medium8Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?
Medium9You compromise a Windows host and dump local account hashes with secretsdump, obtaining the NTLM hash of a local administrator. That same local administrator password was reused across every workstation in the environment. Which technique most directly allows lateral movement to other hosts using that hash without ever recovering the cleartext password?
Hard10In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?
Easy11You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?
Medium12You have obtained a copy of a Windows SAM file from a compromised host. You want to extract the NTLM hashes for offline cracking. Which of the following tools is specifically designed for this task?
Easy13You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?
Hard14You are conducting a penetration test and have obtained a list of usernames. You want to perform a password spray against an OWA (Outlook Web Access) portal. Which tool is specifically designed to automate password spraying against OWA while respecting lockout policies?
Medium15You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?
Medium16You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?
Medium17Refer to the exhibit. What is the primary purpose of the command provided?
Medium18You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?
Easy19During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?
Hard20During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?
Hard21You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)
Medium22During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?
Medium23You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?
EasyOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Password Attacks domain cover on the PEN-200 exam?
- Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
- How many questions are in this domain?
- This page lists all 23 Password Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Password Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.