Courseiva

PEN-200 · topic practice

Password Attacks practice questions

This domain covers credential capture and offline cracking across Windows and Linux targets: NetNTLMv2 challenge-response, AS-REP Roasting, Kerberoasting, /etc/shadow hashes, and encoded credentials in cookies. PEN-200 tests whether you can identify the hash or encoding format, choose the correct tool and mode, and recover plaintext to pivot or escalate.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Password Attacks

What the exam tests

What to know about Password Attacks

Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.

Recognizing hash formats such as NetNTLMv2, AS-REP, Kerberoast, and Linux crypt(3) identifiers like $6$

Selecting Hashcat modes and John the Ripper formats for each captured hash type

Using Responder, Impacket, and Mimikatz to capture or request credentials in Active Directory

Identifying weak encoding like base64 in cookies versus actual encryption or hashing

Watch out for

Common Password Attacks exam traps

  • ▸Treating base64-encoded credentials as secure encryption instead of trivially reversible encoding.
  • ▸Using the wrong Hashcat mode or John format, so cracking fails despite a valid hash and wordlist.
  • ▸Confusing AS-REP Roasting with Kerberoasting; AS-REP requires no Kerberos pre-authentication on the target account.

Practice set

Password Attacks questions

20 questions · select your answer, then reveal the explanation

When performing a password spraying attack against an O365 or Azure AD environment, which TWO factors are most likely to increase the risk of detection or account lockout?

Which THREE of the following are common indicators that an organization is vulnerable to Kerberoasting?

You have gained access to a Linux machine and extracted the shadow file. Which THREE of the following are valid strategies for recovering the plaintext passwords from the hashes provided?

Question 4mediummultiple choice
Read the full Password Attacks explanation →

What is the primary risk of performing a password spray against an organization that has implemented a third-party Single Sign-On (SSO) solution?

Which TWO actions are considered best practices for securing service accounts against password-based attacks?

You are performing a password cracking attack on an encrypted archive that uses a custom KDF (Key Derivation Function). How should you proceed if Hashcat does not support the format natively?

Question 7mediummultiple choice
Read the full Password Attacks explanation →

You are performing a password spraying attack against a web application. You notice that the application returns a specific 403 Forbidden error when a username exists but the password is incorrect, and a 401 Unauthorized error when the username does not exist. How should you adjust your attack strategy?

You are assessing a Linux machine and have read access to /etc/shadow. Which TWO of the following statements regarding the file structure or cracking process are correct?

You are performing a password audit and want to generate targeted candidate passwords based on company-specific terms, years, and common suffixes using Hashcat's rule-based engine. Which built-in Hashcat rule file applies standard capitalization toggles and appends common digit suffixes?

Question 10mediummultiple choice
Read the full Password Attacks explanation →

During an internal penetration test, you capture a Kerberos AS-REP response for a user account that does not require pre-authentication. You save the hash to a file. Which tool and mode should you use to attempt to crack this hash offline?

Question 11mediummultiple choice
Review the full subnetting walkthrough →

During an internal assessment, you capture SMB challenge-response authentications by running Responder on the local subnet. One captured value is a NetNTLMv2 hash for a domain user. You need to determine the most effective next step to obtain the user's cleartext password, assuming no relay opportunities exist and the client has SMB signing enforced. What should you do?

You have obtained a set of NTLM hashes from a Windows domain controller and want to perform a pass-the-hash attack to move laterally. Which TWO of the following tools can be used to authenticate to remote systems using only the NTLM hash? (Choose two.)

You have obtained a set of NTLM hashes from a Windows domain controller during a penetration test. You want to use these hashes to authenticate to other systems without knowing the plaintext passwords. Which TWO of the following techniques allow you to leverage these hashes for lateral movement? (Choose two.)

Question 14mediummultiple choice
Read the full Password Attacks explanation →

You have compromised a Windows host and extracted the local SAM database. You want to crack the NTLM hashes offline. Which of the following hashcat modes should you use for NTLM hashes?

During a penetration test, you gain access to a Windows workstation and extract a Kerberos TGS ticket for a service account from memory using Mimikatz. You suspect the service account's password is weak and want to crack it offline. Which tool and technique should you use?

Question 16mediummultiple choice
Read the full Password Attacks explanation →

You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?

Question 17mediummultiple choice
Read the full Password Attacks explanation →

Refer to the exhibit. What is the primary purpose of the command provided?

Exhibit

hashcat -m 1000 -a 0 hashes.txt rockyou.txt

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

Question 19mediummultiple choice
Read the full Password Attacks explanation →

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Password Attacks sessions

Start a Password Attacks only practice session

Every question in these sessions is drawn from the Password Attacks domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Password Attacks?
Capture the right artifact, identify its exact format, then crack it with the matching Hashcat mode or John format against a wordlist. The single most important thing is matching hash type to tool mode, since a correct hash with the wrong mode never cracks.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Password Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Password Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.