nerdexam
EC-Council

312-49 · Question #669

Gill is a computer forensics investigator who has been called upon to examine a seized computer. This computer, according to the police, was used by a hacker who gained access to numerous banking…

The correct answer is D. Dictionary attack. A dictionary attack is the most likely technique used to crack passwords from SAM (Security Account Manager) files. Dictionary attacks use a pre-compiled wordlist of common passwords, words, and phrases, making them fast and effective against weak or common passwords typically…

Submitted by lukas.cz· Apr 18, 2026Disk Forensics

Question

Gill is a computer forensics investigator who has been called upon to examine a seized computer. This computer, according to the police, was used by a hacker who gained access to numerous banking institutions to steal customer information. After preliminary investigations, Gill finds in the computer's log files that the hacker was able to gain access to these banks through the use of Trojan horses. The hacker then used these Trojan horses to obtain remote access to the companies' domain controllers. From this point, Gill found that the hacker pulled off the SAM files from the domain controllers to then attempt and crack network passwords. What is the most likely password cracking technique used by this hacker to break the user passwords from the SAM files?

Options

  • ASyllable attack
  • BHybrid attack
  • CBrute force attack
  • DDictionary attack

How the community answered

(37 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    5% (2)
  • D
    81% (30)

Explanation

A dictionary attack is the most likely technique used to crack passwords from SAM (Security Account Manager) files. Dictionary attacks use a pre-compiled wordlist of common passwords, words, and phrases, making them fast and effective against weak or common passwords typically used in organizational environments. Since the hacker had already gained remote access and pulled the SAM files, they had time to run an offline dictionary attack. A brute-force attack tries every possible combination and is far slower. Hybrid attacks combine dictionary words with character substitutions, and syllable attacks combine syllables - both are less common and typically slower than a pure dictionary attack in this scenario.

Topics

#Password Cracking#SAM Files#Domain Controller Compromise#Digital Forensics

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice