CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

A client's password policy requires passwords that begin with one uppercase letter, followed by six lowercase letters, and end with one digit, for a total of eight characters. A tester wants to build a hashcat mask attack (attack mode 3) that exactly reflects this policy. Which mask should be used?

  1. A?d?u?l?l?l?l?l?l
  2. B?l?u?u?u?u?u?u?d
  3. C?u?l?l?l?l?l?d?d
  4. D?u?l?l?l?l?l?l?d
Show answer & explanation

Correct answer: D. ?u?l?l?l?l?l?l?d

The policy requires 1 uppercase + 6 lowercase + 1 digit = 8 characters, in that exact order. Option A (?u?l?l?l?l?l?l?d) has 1 uppercase charset, six lowercase charsets, and 1 digit charset, matching the policy precisely. Option B reverses the order (lowercase first), option C puts the digit first, and option D only has 5 lowercase characters with 2 digits, none of which match the stated policy.

Why the other options are wrong

  • A. Places a digit at the start, violating the policy's structure.
  • B. Places a lowercase character first and uppercase letters afterward — wrong order.
  • C. Only includes five lowercase characters and two digits, not matching 6 lowercase + 1 digit.

Hashcat Mask Attack Syntax

A hashcat mask attack (mode 3) defines a per-position character set using placeholders like ?l, ?u, ?d, and ?s to model known password structures.

  • ?l = lowercase letter, ?u = uppercase letter
  • ?d = digit, ?s = special character
  • Masks dramatically reduce keyspace when password structure is known

Memory trick: Build the mask like spelling the password's DNA, position by position

More Vulnerability Discovery and Analysis questions