
GIAC Penetration Tester (GPEN)
Domain 3Objective 2
Password Attacks GPEN Practice Questions (Page 1)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 1–5
- 1
A tester is performing a password spraying attack against a VPN that locks accounts after 5 failed attempts. The tester has a list of 500 usernames and wants to avoid lockouts while testing a set of 10 common passwords. What is the best approach?
Select an answer first - 2
An attacker obtains a list of usernames and passwords from a data breach and tries them on a different website. This is an example of which attack?
Select an answer first - 3
A tester has captured an NTLM hash for a user and a Kerberos TGT for the same user. The tester needs to access a legacy application that only supports NTLM authentication. Which technique should the tester use?
Select an answer first - 4
A tester is cracking passwords for a company that requires passwords to be at least 8 characters and include a number. The tester has a wordlist of common words. Which attack mode is most likely to produce passwords like 'Summer2024'?
Select an answer first - 5
What does a pass-the-ticket attack involve?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.