
EC-CouncilCertified Ethical Hacker
Domain 3Objective 2
Password Cracking and Attacks CEH Practice Questions (Page 4)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 16–20
- 16
A company wants to improve password security but faces user resistance to long passwords. The security team proposes a policy of 8-character complex passwords plus mandatory MFA. Which critique is most valid?
Select an answer first - 17
Which of the following is a recommended best practice for creating a strong password policy?
Select an answer first - 18
What is the purpose of implementing account lockout policies as part of password security?
Select an answer first - 19
A security auditor is reviewing the password practices of a healthcare organization. The organization uses a single shared password for all staff to access a legacy medical device. The auditor wants to reduce the risk of unauthorized access while minimizing disruption to clinical workflows. Which recommendation is the most effective?
Select an answer first - 20
An attacker has a list of hashes and a wordlist of common passwords. The attacker wants to try variations like 'Password1', 'Password!', and 'P@ssword' without manually editing the wordlist. Which attack technique automates these transformations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.