Courseiva

PEN-200 · domain

Password Attacks

This domain covers credential capture and offline cracking across Windows and Linux targets: NetNTLMv2 challenge-response, AS-REP Roasting, Kerberoasting, /etc/shadow hashes, and encoded credentials in cookies. PEN-200 tests whether you can identify the hash or encoding format, choose the correct tool and mode, and recover plaintext to pivot or escalate.

23 questions6 easy12 medium5 hard

Focused practice

Practice Password Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Password Attacks

Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.

Recognizing hash formats such as NetNTLMv2, AS-REP, Kerberoast, and Linux crypt(3) identifiers like $6$

Selecting Hashcat modes and John the Ripper formats for each captured hash type

Using Responder, Impacket, and Mimikatz to capture or request credentials in Active Directory

Identifying weak encoding like base64 in cookies versus actual encryption or hashing

Watch out for

Common Password Attacks exam traps

  • ▸Treating base64-encoded credentials as secure encryption instead of trivially reversible encoding.
  • ▸Using the wrong Hashcat mode or John format, so cracking fails despite a valid hash and wordlist.
  • ▸Confusing AS-REP Roasting with Kerberoasting; AS-REP requires no Kerberos pre-authentication on the target account.

Question index

All Password Attacks questions (23)

Click any question to see the full explanation, or start a practice session above.

1

When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?

Easy
2

You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?

Medium
3

During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?

Medium
4

Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?

Hard
5

You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?

Easy
6

During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?

Medium
7

Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?

Medium
8

Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?

Medium
9

You compromise a Windows host and dump local account hashes with secretsdump, obtaining the NTLM hash of a local administrator. That same local administrator password was reused across every workstation in the environment. Which technique most directly allows lateral movement to other hosts using that hash without ever recovering the cleartext password?

Hard
10

In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?

Easy
11

You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?

Medium
12

You have obtained a copy of a Windows SAM file from a compromised host. You want to extract the NTLM hashes for offline cracking. Which of the following tools is specifically designed for this task?

Easy
13

You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?

Hard
14

You are conducting a penetration test and have obtained a list of usernames. You want to perform a password spray against an OWA (Outlook Web Access) portal. Which tool is specifically designed to automate password spraying against OWA while respecting lockout policies?

Medium
15

You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?

Medium
16

You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?

Medium
17

Refer to the exhibit. What is the primary purpose of the command provided?

Medium
18

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

Easy
19

During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?

Hard
20

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?

Hard
21

You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)

Medium
22

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

Medium
23

You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?

Easy

Frequently asked questions

What does the Password Attacks domain cover on the PEN-200 exam?
Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
How many questions are in this domain?
This page lists all 23 Password Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Password Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
offsec-oscp OFFSEC-OSCP password attacks Practice Questions