
GIAC Penetration Tester (GPEN)
Domain 3Objective 1
Password Formats and Hashes GPEN Practice Questions (Page 8)
Part of the Password Attacks and Credential Attacks domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–34 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 36–39
- 36
A company is migrating from a legacy system that stores unsalted MD5 hashes to a modern system. The security team wants to upgrade to a salted, slow hash function, but the migration must not require users to reset passwords. Which approach is the most secure and practical?
Select an answer first - 37
A security analyst is reviewing a list of hashes from different systems. One hash is `e99a18c428cb38d5f260853678922e03` and another is `5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8`. Which statement correctly identifies these hashes?
Select an answer first - 38
A developer is implementing password storage and wants to use a unique salt per user. They are considering two approaches: (1) storing the salt in a separate column in the database, and (2) embedding the salt in the hash string (e.g., `$6$salt$hash`). Which approach is more secure?
Select an answer first - 39
Which password cracking technique uses a precomputed table of hashes for common passwords to quickly reverse a hash?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GPEN
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.