
GIAC Penetration Tester (GPEN)
Domain 3Objective 2
Password Attacks GPEN Practice Questions (Page 6)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 26–30
- 26
During an Active Directory assessment, a tester obtains a Kerberos service ticket for a domain admin account by compromising a service account. The tester wants to impersonate that admin to access a database server. Which attack should the tester use?
Select an answer first - 27
A tester has a wordlist containing 'password', 'admin', and 'welcome'. The tester wants to generate variations like 'Password1!', 'Admin2024', and 'welcome#1'. Which technique is most appropriate?
Select an answer first - 28
A tester has administrative access to a domain controller and extracts a Kerberos ticket-granting ticket (TGT) for a domain admin. The tester wants to impersonate that admin to access a web application that uses Kerberos authentication. Which technique should the tester use?
Select an answer first - 29
Which scenario best exemplifies a hybrid attack?
Select an answer first - 30
A tester is cracking hashes from a company that has a password policy requiring at least one uppercase letter and one number. The tester has a wordlist of lowercase base words. Which Hashcat attack mode is best suited to generate candidates like 'Summer2024'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.