Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 3Objective 3

Attacking Password Hashes GPEN Practice Questions (Page 6)

Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts

Questions 26–30

  1. 26application · medium

    During an internal penetration test, you retrieve a Windows SAM file from a compromised workstation. The extracted hash for a local admin account is 64 hex characters and starts with 'aad3b435b51404eeaad3b435b51404ee'. You need to crack the actual password to test password reuse across the domain. Which approach is most appropriate?

    Select an answer first
  2. 27application · medium

    A company stores user passwords as unsalted MD5 hashes. To mitigate offline cracking, which change is most effective?

    Select an answer first
  3. 28foundation · easy

    Which Windows privilege is commonly required to impersonate another user's token?

    Select an answer first
  4. 29foundation · easy

    What does a pass-the-hash attack allow an attacker to do?

    Select an answer first
  5. 30foundation · easy

    In a pass-the-ticket attack, which Kerberos ticket is often targeted to impersonate a user?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.