
GIAC Penetration Tester (GPEN)
Domain 3Objective 1
Password Formats and Hashes GPEN Practice Questions (Page 7)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 31–35
- 31
Which property of a cryptographic hash function makes it infeasible to reverse the hash to find the original input?
Select an answer first - 32
A system administrator wants to migrate from unsalted MD5 to a more secure password storage scheme. Which option best addresses the weaknesses of unsalted MD5?
Select an answer first - 33
During a penetration test, you retrieve a Linux shadow file. One entry contains a hash that starts with `$6$` followed by a 16-character salt and a long string of characters. Which hash algorithm and defensive property does this entry most likely represent?
Select an answer first - 34
A development team is migrating a legacy user database to a new authentication service. The old system stored unsalted SHA-256 hashes, and the team wants to prevent rainbow table attacks without forcing all users to reset passwords. Which approach best meets this requirement?
Select an answer first - 35
A penetration tester is attempting to crack a set of bcrypt hashes. The tester has a wordlist and a GPU. Which approach is most effective given that bcrypt is designed to be slow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.