
EC-CouncilCertified Security Specialist
Domain 3Objective 5
Password Cracking Techniques and Countermeasures ECSS Practice Questions (Page 2)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
38questions here
8free pages
5concepts
Questions 6–10
- 6
Which of the following is an effective countermeasure to slow down brute-force attacks?
Select an answer first - 7
A web application currently stores passwords using unsalted SHA-1 hashes. The development team wants to migrate to a more secure storage mechanism. Which option provides the best protection against offline cracking attacks?
Select an answer first - 8
Which countermeasure is most effective in preventing rainbow table attacks?
Select an answer first - 9
A small company stores user passwords as unsalted SHA-256 hashes. After a breach, an attacker quickly recovered many passwords using precomputed lookup tables. The company wants to improve password storage without forcing an immediate password reset for all users. Which countermeasure should be implemented first?
Select an answer first - 10
A company's authentication system uses a password-based key derivation function (PBKDF2) with a high iteration count. An attacker has obtained the password database. Which statement best describes the impact of the high iteration count?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.