A security consultant was hired to audit a company's password are account policy. The company implements the following controls: Minimum password length: 16 Maximum password age: 0 Minimum password age: 0 Password complexity: disabled Store passwords in plain text: disabled Failed attempts lockout: 3 Lockout timeout: 1 hour The password database uses salted hashes and PBKDF2. Which of the following is MOST likely to yield the greatest number of plain text passwords in the shortest amount of time?
A) Offline hybrid dictionary attack
B) Offline brute-force attack
C) Online hybrid dictionary password spraying attack
D) Rainbow table attack
E) Online brute-force attack
F) Pass-the-hash attack
Correct Answer:
Verified
Q349: A systems administrator has deployed the latest
Q350: A security architect has designated that a
Q351: A Chief Information Security Officer (CISO) is
Q352: A cybersecurity consulting company supports a diverse
Q353: An enterprise's Chief Technology Officer (CTO) and
Q355: Which of the following may indicate a
Q356: A security analyst for a bank received
Q357: A company recently experienced a security incident
Q358: A systems analyst is concerned that the
Q359: A Chief Information Security Officer (CISO) needs
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents