
GIAC Penetration Tester (GPEN)
Domain 3Objective 4
Advanced Password Attacks GPEN Practice Questions (Page 6)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
15concepts
Questions 26–30
- 26
You are cracking a large set of bcrypt hashes with a high cost factor. You have access to a single GPU workstation and a budget for cloud resources. Which approach would most effectively reduce the time to crack the hashes?
Select an answer first - 27
During a penetration test, you recover a set of NTLM hashes from a domain controller. The domain password policy enforces a minimum of 8 characters, and your OSINT shows the company uses the pattern 'SeasonYear' for service accounts (e.g., Summer2024). You have a wordlist of seasons and years. Which attack strategy would most efficiently crack these hashes?
Select an answer first - 28
In Hashcat, what does the rule 'c' do when applied to a word?
Select an answer first - 29
During an internal test, you obtain the NTLM hash of a domain admin from a memory dump. You want to move laterally to a file server that does not enforce SMB signing. Which technique would allow you to authenticate without knowing the plaintext password?
Select an answer first - 30
During an assessment, you find a service account with a SPN and a weak password. You want to obtain the password hash for offline cracking. Which attack should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.