Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 3Objective 1

Password Formats and Hashes GPEN Practice Questions (Page 1)

Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
6concepts

Questions 1–5

  1. 1foundation · easy

    Which password cracking technique involves trying every possible combination of characters up to a certain length?

    Select an answer first
  2. 2expert · hard

    A company is migrating from a legacy system that uses unsalted MD5 hashes to a new system that uses bcrypt with a per-user salt. During the transition, both systems are active. An attacker has obtained the hash database from both systems. Which statement about the attacker's ability to crack passwords is accurate?

    Select an answer first
  3. 3foundation · easy

    Which hash algorithm produces a 128-bit hash value and is considered cryptographically broken for many security purposes due to collision vulnerabilities?

    Select an answer first
  4. 4application · medium

    A system administrator finds a file with lines like `$apr1$salt$hash` and needs to identify the hash type. Which algorithm is indicated by the `$apr1$` prefix?

    Select an answer first
  5. 5foundation · easy

    Why does salting make dictionary attacks more difficult for an attacker who has obtained a database of password hashes?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.