
GIAC Penetration Tester (GPEN)
Domain 3Objective 1
Password Formats and Hashes GPEN Practice Questions (Page 5)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 21–25
- 21
You are tasked with cracking a set of password hashes that are salted with a unique salt per user. Which attack method is most likely to succeed within a reasonable time?
Select an answer first - 22
Which password storage format stores the user's password in a reversible form, allowing the original value to be recovered if the encryption key is known?
Select an answer first - 23
You are performing a password audit for a company that uses two different systems. System A stores passwords as unsalted MD5 hashes. System B stores passwords as salted SHA-256 hashes with a unique salt per user. You have a limited time budget and want to crack as many passwords as possible. Which approach is most efficient?
Select an answer first - 24
Which property of a cryptographic hash function ensures that the same input always produces the same output?
Select an answer first - 25
What is the primary purpose of adding a unique salt to each password before hashing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.