
EC-CouncilCertified Security Specialist
Domain 3Objective 5
Password Cracking Techniques and Countermeasures ECSS Practice Questions (Page 6)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
38questions here
8free pages
5concepts
Questions 26–30
- 26
A security analyst is testing the password policy of a web application. The application stores passwords as salted hashes. The analyst has a wordlist of common passwords and wants to crack passwords that follow the pattern of a common word followed by two digits (e.g., 'summer99', 'winter01'). Which attack technique is most efficient for this specific pattern?
Select an answer first - 27
During a security assessment, a penetration tester extracts a database of password hashes. The hashes are unsalted MD5 values. The tester wants to recover as many plaintext passwords as possible in the shortest time, knowing that many users choose common words with simple substitutions. Which approach should the tester prioritize?
Select an answer first - 28
Which password storage mechanism is considered the most secure among the following?
Select an answer first - 29
A company is migrating from a legacy system that stores passwords as unsalted SHA-1 hashes to a modern system using bcrypt. The migration must not force all users to reset their passwords immediately. Which approach best balances security and user experience?
Select an answer first - 30
A company's IT department discovered that an attacker obtained the password hash database from their authentication server. The hashes are salted and use a strong hashing algorithm. The IT manager wants to implement additional countermeasures to reduce the risk of successful password cracking. Which countermeasure would be most effective in this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.