Courseiva
Password Attacks →easyMultiple Choice

PEN-200 Password Attacks Practice Question

In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A transformation applied to dictionary words to simulate common password modifications.

Rules allow attackers to transform wordlist entries into more complex passwords, such as adding numbers, changing casing, or substituting characters. This is a critical technique because it allows a small wordlist to cover a much larger search space of possible passwords. Mastering rules is essential for efficient credential recovery, as it enables the simulation of common user password creation habits without needing massive, unmanageable wordlists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A predefined security policy set by the organization to ensure password complexity.

    Why it's wrong here

    A security policy is a set of rules enforced by an organization, but this is entirely different from the 'rules' used in password cracking tools. Confusing organizational policy with tool-specific functionality is a conceptual error that could lead to misunderstandings about how cracking software operates.

  • ✓

    A transformation applied to dictionary words to simulate common password modifications.

    Why this is correct

    Rules are a set of instructions applied to words in a dictionary. For example, a rule might convert 'password' into 'Password123!'. This significantly increases the effectiveness of a dictionary attack by covering common user habits like capitalizing the first letter or appending special characters to a base word.

  • ✗

    A configuration setting that defines the maximum length of the cracked password.

    Why it's wrong here

    Limiting password length is usually handled by the cracking tool's command-line arguments or specific algorithm constraints, not by 'rules'. Rules are meant for mutation, not for defining the boundaries or constraints of the cracking process itself, which are generally set at the start of the execution.

  • ✗

    A list of known leaked passwords that the tool compares against the hash directly.

    Why it's wrong here

    A list of leaked passwords is referred to as a wordlist or dictionary file, not a rule. Rules are the logic applied to the wordlist, not the wordlist itself. Confusing these terms leads to a poor understanding of how to configure and execute effective password cracking campaigns.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.