
GIAC Penetration Tester (GPEN)
Domain 3Objective 2
Password Attacks GPEN Practice Questions (Page 7)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 31–35
- 31
A tester uses a wordlist containing 'Summer' and applies a rule that appends '2024' to each word. Which attack technique is being used?
Select an answer first - 32
A tester has a large set of unsalted MD5 password hashes from a legacy system. The tester wants to recover plaintext passwords as quickly as possible with limited GPU resources. Which approach is most efficient?
Select an answer first - 33
Why is credential stuffing often successful?
Select an answer first - 34
During a penetration test, a tester captures password hashes from a compromised system and then attempts to crack them offline on a powerful workstation. Which statement best describes this approach?
Select an answer first - 35
A tester needs to determine whether a password is weak. The tester has access to a hash of the password and can attempt unlimited offline guesses. Which type of attack is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.