
EC-CouncilCertified Security Specialist
Domain 3Objective 5
Password Cracking Techniques and Countermeasures ECSS Practice Questions (Page 5)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
38questions here
8free pages
5concepts
Questions 21–25
- 21
A security analyst has captured a set of password hashes from a compromised server. The hashes are salted with a unique salt per user. The analyst has limited time and wants to crack as many passwords as possible. Which strategy is most effective?
Select an answer first - 22
A company has just experienced a data breach where the password hash database was stolen. The hashes are salted and use a strong algorithm. The security team must decide on countermeasures to mitigate the impact. The company has a large user base, and forcing an immediate password change for all users would cause significant operational disruption. Which countermeasure balances security and operational impact?
Select an answer first - 23
A company is implementing a new password policy. The security team wants to prevent both online brute-force attacks and offline cracking of stolen hashes. The company has a large user base and wants to minimize user frustration. Which combination of countermeasures is most effective?
Select an answer first - 24
During a penetration test, a security analyst captures the following password hashes from a Linux system: 'root:$6$salt123$hashvalue...' and 'alice:$6$salt456$hashvalue...'. The analyst notices that both hashes use the SHA-512 crypt format with different salts. The analyst has a wordlist of 10 million common passwords and needs to test them against both accounts. Which attack technique is most appropriate for this scenario?
Select an answer first - 25
A penetration tester is assessing a network and has captured NTLMv2 hashes from a Windows environment. The tester has access to a powerful GPU workstation and needs to crack these hashes. The hashes are known to be derived from passwords that follow a corporate policy requiring at least 8 characters with a mix of uppercase, lowercase, digits, and symbols. Which tool and attack strategy is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.