
GIAC Penetration Tester (GPEN)
Domain 3Objective 4
Advanced Password Attacks GPEN Practice Questions (Page 4)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
15concepts
Questions 16–20
- 16
In Hashcat, what does the mask '?u?l?l?l?d?d' represent?
Select an answer first - 17
What does the prefix '$2y$' in a hash string typically indicate?
Select an answer first - 18
Which tool is commonly used for password cracking and supports GPU acceleration to speed up attacks?
Select an answer first - 19
You have captured a large number of bcrypt hashes from a Linux server. Your workstation has a high-end GPU, but the cracking speed is only 1,000 hashes per second. You need to test a 10-million-word dictionary with 50 rules. What is the most practical approach to complete this task in a reasonable time?
Select an answer first - 20
Which of the following is a feature of John the Ripper that allows it to automatically detect many common hash types?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.