ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 246 - PT0-002 discussion

Report
Export

During an assessment, a penetration tester obtains a list of 30 email addresses by crawling the target company's website and then creates a list of possible usernames based on the email address format.

Which of the following types of attacks would MOST likely be used to avoid account lockout?

A.
Mask
Answers
A.
Mask
B.
Rainbow
Answers
B.
Rainbow
C.
Dictionary
Answers
C.
Dictionary
D.
Password spraying
Answers
D.
Password spraying
Suggested answer: D

Explanation:

Password spraying is a type of password guessing attack that involves trying one or a few common passwords against many usernames or accounts. Password spraying can avoid account lockout policies that limit the number of failed login attempts per account by spreading out the attempts over time and across different accounts. Password spraying can also increase the chances of success by using passwords that are likely to be used by many users, such as default passwords, seasonal passwords, or company names. Mask is a type of password cracking attack that involves using a mask or a pattern to generate passwords based on known or guessed characteristics of the password, such as length, case, or symbols. Rainbow is a technique of storing precomputed hashes of passwords in a table that can be used to quickly crack passwords by looking up the hashes. Dictionary is a type of password cracking attack that involves using a wordlist or a dictionary of common or likely passwords to try against an account.

asked 02/10/2024
Katlego Nkwane
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first