
GIAC Penetration Tester (GPEN)
Domain 3Objective 3
Attacking Password Hashes GPEN Practice Questions (Page 4)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
Questions 16–20
- 16
You have compromised a domain-joined Windows machine and extracted a Kerberos TGT for a user. You need to access a web application that is integrated with Active Directory and uses Kerberos authentication. What is the most direct way to use the TGT?
Select an answer first - 17
What is token impersonation in the context of Windows privilege escalation?
Select an answer first - 18
What is the primary difference between pass-the-hash and pass-the-ticket attacks?
Select an answer first - 19
You have a list of 10,000 NTLM hashes from a domain. You need to crack as many as possible within 24 hours. You have a GPU workstation with Hashcat. Which attack strategy is most efficient?
Select an answer first - 20
A penetration tester extracts a 32-character hexadecimal string from a Windows SAM file. Which hash type is this most likely to be?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.