
EC-CouncilCertified Ethical Hacker
Domain 3Objective 2
Password Cracking and Attacks CEH Practice Questions (Page 7)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 31–35
- 31
How does a rainbow table attack work?
Select an answer first - 32
During a penetration test, you capture the NTLM hash of a domain user's password. The password is known to follow the pattern of a common word followed by two digits (e.g., 'Summer01'). You have a wordlist of common words but no precomputed hashes. Which attack method is most efficient to recover the plaintext?
Select an answer first - 33
A penetration tester needs to test the strength of passwords for a web application that locks an account after five failed attempts. The tester has obtained a copy of the password hashes from a backup. Which approach should the tester use to avoid triggering the lockout policy?
Select an answer first - 34
A company's authentication database was breached, and the attacker obtained hashes. The hashes were generated with a fast algorithm and no salt. The company wants to prevent the attacker from cracking the hashes while also improving future security. Which action is most effective?
Select an answer first - 35
A development team is designing a new authentication system. They want to store passwords securely and resist both rainbow table and brute-force attacks. Which storage approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.