
GIAC Penetration Tester (GPEN)
Domain 3Objective 2
Password Attacks GPEN Practice Questions (Page 2)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 6–10
- 6
A tester needs to crack a password hash that is known to be exactly 4 characters long, using only lowercase letters. The tester has no wordlist. Which attack mode is most suitable?
Select an answer first - 7
A penetration tester wants to avoid locking out user accounts while attempting to guess passwords. Which technique is most appropriate?
Select an answer first - 8
A security analyst discovers that many employees use the same email address and password on both the corporate VPN and a popular third-party shopping site. The shopping site recently suffered a data breach. Which attack is the analyst most concerned about?
Select an answer first - 9
A company is experiencing a high volume of failed login attempts across its VPN and email systems. The security team suspects both password spraying and credential stuffing. They want to implement controls that reduce the risk of both attacks while minimizing impact on legitimate users. Which combination of controls is most effective?
Select an answer first - 10
A security team discovers that several employees use the same password on a corporate portal and on a third-party shopping site that was breached. The team suspects attackers are logging in with the breached credentials. Which attack are the attackers most likely performing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.