Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 3Objective 2

Password Attacks GPEN Practice Questions (Page 8)

Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
12concepts

Questions 36–40

  1. 36foundation · easy

    Which protocol is most commonly associated with pass-the-hash attacks?

    Select an answer first
  2. 37application · medium

    A tester is performing an offline crack of a Linux shadow file. The tester has a standard wordlist but suspects users have chosen passwords based on the company name 'Acme' with common variations. Which approach would most efficiently test these variations?

    Select an answer first
  3. 38foundation · easy

    What is the main disadvantage of a pure brute-force attack?

    Select an answer first
  4. 39foundation · easy

    In password cracking, what is the purpose of a rule in a rule-based attack?

    Select an answer first
  5. 40application · medium

    During an internal penetration test, a tester captures an NTLM hash of a domain user from a compromised workstation. The tester needs to access a file server that accepts NTLM authentication. The tester does not know the plaintext password. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.