
GIAC Penetration Tester (GPEN)
Domain 3Objective 1
Password Formats and Hashes GPEN Practice Questions (Page 6)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 26–30
- 26
Which hash algorithm is commonly used in Windows for storing password hashes in the SAM database and is based on the MD4 hash function?
Select an answer first - 27
A web application stores passwords using a salted hash. The developer argues that because each password is salted, rainbow table attacks are completely impossible. Which response is most accurate?
Select an answer first - 28
During a Windows penetration test, you extract the local SAM database and find entries like `Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::`. What is the second hash (the 32-character value after the first colon pair) and what attack is it most vulnerable to?
Select an answer first - 29
You are analyzing a captured hash that appears as `$2y$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy`. Which hash algorithm and characteristic is most likely correct?
Select an answer first - 30
During an engagement, you capture a Windows authentication challenge. The response is a 16-byte value that you suspect is an NTLM hash. Which characteristic confirms this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.