Skip to content
ScopefileGet the app

Technique fileSystem hacking

Password attacks and the defense that stops each one

Password attacks come in two settings: online guessing against a live login, and offline cracking of stolen hashes. Dictionary, brute force, rule and mask, rainbow tables and credential stuffing each meet a different control: lockout, salting, slow hashing or MFA.

Exam
312-50
Domain
3 · System hacking
Targets
8

Online or offline decides the defense

These attacks sit in the System Hacking module, and the attack names are the cheap half. The useful half is the pairing: which control actually stops which attack. Build one table of pairs, drill it, move on.

Online attacks run against a live login, so the server's own limits (throttling, lockout, a second factor) shape what the attacker can do. Offline attacks run against hashes copied off a system, with no server in the loop. Whatever protects an offline hash has to be built into how it was stored.

The attack categories

Dictionary attack
Tries entries from a wordlist. Fast, and blind to anything not on the list.
Brute force
Works through the whole keyspace. Certain to finish eventually; the time cost grows steeply with length.
Rule and mask attacks
Shrink the search by encoding what the attacker knows or guesses about how people build passwords.
Rainbow table
A precomputed lookup from hash to password, trading disk space for cracking time.
Credential stuffing
Replays username and password pairs leaked in other breaches, betting on reuse.
Password spraying
Tries a few very common passwords against a long list of accounts.

Attack against defense

Which control counters each attack
AttackSettingCounter
DictionaryOnline or offlineLong passphrases; a blocklist of common and breached passwords
Brute forceOnlineThrottling or lockout after failed attempts
Brute forceOfflineA slow, salted hashing scheme
Rainbow tableOfflineA unique salt per user
Credential stuffingOnlineMulti-factor authentication; breached-password checks
Password sprayingOnlineMFA; alerts on one password tried across many accounts

Name it, then stop it

Sort each case online or offline first; the control follows.

Answered 0/8Hits 0

T-01

Which of the following is a common tool used in password cracking that employs known phrases and words from a list?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASalting is a defense that adds unique random data to each password before hashing, not a cracking method.
  2. BRainbow table attacks look up hashes in precomputed chains rather than trying words from a list.
  3. CCorrect: a dictionary attack tries candidate passwords drawn from wordlists of common words, phrases and previously leaked passwords.
  4. DBrute force tries every possible character combination rather than relying on a curated wordlist.
T-02

Which password cracking technique involves trying every possible combination of characters until the correct password is found?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: brute force exhaustively tries every combination in a character set, which always succeeds eventually but scales badly with length.
  2. BSocial engineering tricks people into revealing passwords rather than computing guesses.
  3. CRainbow table attacks look up precomputed hash chains rather than generating every combination at attack time.
  4. DDictionary attacks only try words from a list, so they do not cover every possible combination.
T-03

Which password cracking technique involves comparing the hash of a password against a database of pre-computed hashes?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: rainbow table attacks look up captured hashes in precomputed chains, trading storage for speed, which per-user salts defeat.
  2. BBrute force computes and tests every combination live, rather than consulting precomputed hashes.
  3. CRule-based attacks transform dictionary words with patterns such as substitutions and appended digits, computing hashes on the fly.
  4. DDictionary attacks hash wordlist entries at attack time instead of matching against a precomputed database.
T-04

Which password cracking attack is MOST effective against passwords that use common words with simple substitutions (e.g., 'p@ssw0rd')?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: rule-based attacks apply transformations such as letter-to-symbol swaps and appended digits to dictionary words, which targets passwords like p@ssw0rd.
  2. BA birthday attack exploits the probability of hash collisions and is not a method for guessing human-chosen passwords.
  3. CRainbow tables only help with unsalted hashes and are not tailored to predictable word mangling patterns.
  4. DBrute force would eventually find such a password but wastes enormous effort compared with targeting predictable substitutions.
T-05

Which password cracking approach uses patterns and known character positions to reduce the search space?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARainbow table attacks use precomputed hash chains rather than patterns of known character positions.
  2. BDictionary attacks try whole words from a list rather than defining which character type belongs at each position.
  3. CRelay attacks forward authentication exchanges between parties instead of guessing passwords.
  4. DCorrect: mask attacks define character types per position, such as an uppercase letter followed by lowercase and two digits, shrinking the brute force search space.
T-06

An attacker intends to compromise an external authentication portal that automatically locks user accounts after five consecutive failed login attempts. Which technique should be employed to avoid triggering this threshold-based security control?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARainbow tables crack captured hashes offline and do not interact with an online login portal or its lockout counter.
  2. BCorrect: credential stuffing tries one leaked username and password pair per account, so per-account lockout thresholds rarely trigger; MFA and breached-password checks counter it.
  3. CBoolean blind injection is a SQL injection technique, not a way to guess credentials against a login portal.
  4. DVertical brute forcing hammers a single account with many passwords, which is exactly what a lockout threshold is designed to stop.
T-07

A junior analyst retrieves an /etc/shadow file during a penetration test and immediately suggests utilizing a massive rainbow table to recover the passwords. Why will this approach fail?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe kernel does not block cracking attempts; a rainbow table attack happens offline on the attacker's own hardware.
  2. BHash algorithms do not change key size during table generation; hashing does not even use a key.
  3. CRainbow tables can be built for any unsalted hash format, not only Windows LM and NTLM.
  4. DCorrect: modern Linux shadow entries use unique per-user salts with slow algorithms like SHA-512 crypt or yescrypt, making precomputed tables useless.
T-08

A public-facing web portal is experiencing a high volume of automated login attempts utilizing lists of compromised usernames and passwords. Which compensating control is BEST suited to mitigate this specific threat vector?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAggressive lockout barely slows stuffing, which tries one pair per account, and it lets attackers lock out legitimate users on purpose.
  2. BCorrect: multi-factor authentication makes a stolen username and password insufficient on its own, directly neutralizing credential stuffing.
  3. CStuffing campaigns rotate through large pools of residential IP addresses, so blocking known bad sources has limited effect.
  4. DStronger complexity rules do not help when attackers already hold the exact plaintext passwords leaked from other breaches.

Storage and policy

What makes an attack online or offline?

Whether a live authentication service is in the loop. If every guess goes to a login page or service, it is online and the server can slow it down. If the attacker works on a copy of the stored hashes, it is offline and only the storage scheme stands in the way.

Why does current guidance drop forced password changes?

Routine changes push users toward predictable variations of the old password. NIST SP 800-63B-4 asks for a change only when there is evidence of compromise, and puts weight on length and blocklist screening instead (checked Oct 11, 2026).

How should a system store passwords?

Salted and hashed with a deliberately slow scheme, never encrypted or in plain text. Hashing is one-way by design, a point covered in symmetric vs asymmetric vs hashing.

Sources