
GIAC Penetration Tester (GPEN)
Domain 3Objective 4
Advanced Password Attacks GPEN Practice Questions (Page 9)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
15concepts
Questions 41–45
- 41
You are testing a web application that locks accounts after 5 failed attempts within 15 minutes. You have a list of 1,000 usernames and a small list of common passwords. What is the best approach to avoid triggering lockouts while still testing many accounts?
Select an answer first - 42
You are testing a system that stores SHA-256 hashes without salt. The password policy requires exactly 8 characters, with at least one uppercase, one lowercase, and one digit. You have a GPU that can test 10 billion hashes per second. You need to crack as many hashes as possible within 24 hours. Which attack strategy is most efficient?
Select an answer first - 43
You are cracking NTLM hashes from a domain where the password policy requires at least 8 characters and complexity. Your wordlist contains common words, but you need to generate variations that include common substitutions (e.g., 'a' -> '@', 'e' -> '3') and append a digit. Which rule set would be most efficient?
Select an answer first - 44
What is the primary benefit of using GPU acceleration in password cracking?
Select an answer first - 45
Why is Kerberoasting considered an offline attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.