Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 3Objective 2

Password Cracking and Attacks CEH Practice Questions (Page 4)

Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 16–20

  1. 16expert · hard

    A company wants to improve password security but faces user resistance to long passwords. The security team proposes a policy of 8-character complex passwords plus mandatory MFA. Which critique is most valid?

    Select an answer first
  2. 17foundation · easy

    Which of the following is a recommended best practice for creating a strong password policy?

    Select an answer first
  3. 18foundation · easy

    What is the purpose of implementing account lockout policies as part of password security?

    Select an answer first
  4. 19expert · hard

    A security auditor is reviewing the password practices of a healthcare organization. The organization uses a single shared password for all staff to access a legacy medical device. The auditor wants to reduce the risk of unauthorized access while minimizing disruption to clinical workflows. Which recommendation is the most effective?

    Select an answer first
  5. 20application · medium

    An attacker has a list of hashes and a wordlist of common passwords. The attacker wants to try variations like 'Password1', 'Password!', and 'P@ssword' without manually editing the wordlist. Which attack technique automates these transformations?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.