
GIAC Penetration Tester (GPEN)
Domain 3Objective 4
Advanced Password Attacks GPEN Practice Questions (Page 2)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
15concepts
Questions 6–10
- 6
Which attack method is most appropriate when you have a list of common passwords and want to test them against many user accounts without triggering lockouts?
Select an answer first - 7
Which tool is commonly used to extract password hashes from a Windows memory dump?
Select an answer first - 8
You have compromised a domain user account and are on a workstation. You need to move laterally to a server. You have the ability to extract Kerberos tickets from memory. Which attack would allow you to reuse a service ticket to access the server without knowing the password?
Select an answer first - 9
You are advising a company that stores passwords as unsalted SHA-256 hashes. They are considering using rainbow tables to speed up cracking during a security audit. What is the main limitation of rainbow tables in this scenario?
Select an answer first - 10
You have a mix of hash types: 1,000 NTLM hashes, 500 SHA-1 hashes, and 100 bcrypt hashes. Your GPU rig can crack NTLM at 100 GH/s, SHA-1 at 50 GH/s, and bcrypt at 10 kH/s. You have a 24-hour window. Which approach is most effective to maximize the number of cracked hashes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.