Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 3Objective 5

Password Cracking Techniques and Countermeasures ECSS Practice Questions (Page 5)

Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.

38questions here
8free pages
5concepts

Questions 21–25

  1. 21expert · hard

    A security analyst has captured a set of password hashes from a compromised server. The hashes are salted with a unique salt per user. The analyst has limited time and wants to crack as many passwords as possible. Which strategy is most effective?

    Select an answer first
  2. 22expert · hard

    A company has just experienced a data breach where the password hash database was stolen. The hashes are salted and use a strong algorithm. The security team must decide on countermeasures to mitigate the impact. The company has a large user base, and forcing an immediate password change for all users would cause significant operational disruption. Which countermeasure balances security and operational impact?

    Select an answer first
  3. 23expert · hard

    A company is implementing a new password policy. The security team wants to prevent both online brute-force attacks and offline cracking of stolen hashes. The company has a large user base and wants to minimize user frustration. Which combination of countermeasures is most effective?

    Select an answer first
  4. 24application · medium

    During a penetration test, a security analyst captures the following password hashes from a Linux system: 'root:$6$salt123$hashvalue...' and 'alice:$6$salt456$hashvalue...'. The analyst notices that both hashes use the SHA-512 crypt format with different salts. The analyst has a wordlist of 10 million common passwords and needs to test them against both accounts. Which attack technique is most appropriate for this scenario?

    Select an answer first
  5. 25expert · hard

    A penetration tester is assessing a network and has captured NTLMv2 hashes from a Windows environment. The tester has access to a powerful GPU workstation and needs to crack these hashes. The hashes are known to be derived from passwords that follow a corporate policy requiring at least 8 characters with a mix of uppercase, lowercase, digits, and symbols. Which tool and attack strategy is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.