
EC-CouncilCertified Ethical Hacker
Domain 3Objective 2
Password Cracking and Attacks CEH Practice Questions (Page 6)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 26–30
- 26
Which of the following is a known vulnerability of using unsalted MD5 for password storage?
Select an answer first - 27
A penetration tester is performing an assessment of a web application. The tester wants to test the login form for weak passwords without triggering account lockouts. Which technique is most appropriate?
Select an answer first - 28
A penetration tester has captured a set of NTLM hashes from a Windows domain. The tester knows the organization enforces a password policy that requires at least 8 characters, but many users still choose common words with predictable substitutions (e.g., 'Password1'). The tester wants to maximize the number of cracked hashes in the shortest time. Which approach is most effective?
Select an answer first - 29
Why is password security considered a critical aspect of system hacking defense?
Select an answer first - 30
Which of the following is a feature of John the Ripper?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.