CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A password policy requires exactly 8 characters formatted as one uppercase letter, followed by five lowercase letters, followed by two digits. Using a hashcat mask attack with the mask ?u?l?l?l?l?l?d?d, how many total password combinations must be tested?

  1. A26^8 ≈ 2.09 × 10^11
  2. B95^8 ≈ 6.63 × 10^15
  3. C62^8 ≈ 2.18 × 10^14
  4. D26 × 26^5 × 10^2 ≈ 3.09 × 10^10
Show answer & explanation

Correct answer: D. 26 × 26^5 × 10^2 ≈ 3.09 × 10^10

The mask ?u?l?l?l?l?l?d?d specifies one uppercase (26 options), five lowercase (26 options each), and two digits (10 options each): 26 × 26^5 × 10^2 = 26 × 11,881,376 × 100 = 30,891,577,600 ≈ 3.09 × 10^10. The other options represent brute-forcing the full printable set (95^8), all alphanumeric characters (62^8), or all uppercase-only (26^8), none of which match the known character-position structure exploited by the mask.

Why the other options are wrong

  • A. 26^8 assumes all positions are letters only, ignoring the two digit positions.
  • B. 95^8 assumes every position could be any printable character, ignoring the known structure.
  • C. 62^8 assumes full alphanumeric charset at every position, ignoring the fixed pattern.

Hashcat Mask Attack

A targeted brute-force technique that defines the character set for each position in a password based on a known or suspected pattern, drastically reducing keyspace versus full brute force.

  • ?u = uppercase, ?l = lowercase, ?d = digit, ?s = special
  • Keyspace = product of charset sizes per position
  • Far more efficient than full charset brute force when policy/pattern is known

Memory trick: 'Mask the password's shape and hashcat needs far fewer guesses'

More Attacks and Exploits questions