
GIAC Penetration Tester (GPEN)
Domain 3Objective 2
Password Attacks GPEN Practice Questions (Page 11)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 51–55
- 51
In which environment is a pass-the-ticket attack most relevant?
Select an answer first - 52
What is a major limitation of rainbow table attacks?
Select an answer first - 53
A penetration tester is assessing a web application that uses a poorly-designed login API. The API returns a generic 'invalid credentials' error for both wrong username and wrong password, but it also returns a different HTTP status code when the account is locked. The tester has a list of 500 usernames and wants to identify valid usernames without causing a full account lockout. The lockout policy is 10 failed attempts per 15 minutes. Which approach is most effective?
Select an answer first - 54
A penetration tester is assessing a company that enforces a 5-attempt account lockout policy. The tester has a list of 2,000 usernames and wants to test password strength without triggering a widespread lockout. Which approach best fits the constraint?
Select an answer first - 55
A tester is using John the Ripper to crack hashes. The tester has a wordlist and wants to generate variations like 'Password1!', 'p@ssw0rd', and 'Admin2024'. Which configuration is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.