
EC-CouncilEthical Hacking Essentials
Domain 2Objective 5
Password Cracking Countermeasures EHE Practice Questions (Page 1)
Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.
44questions here
9free pages
7concepts
Questions 1–5
- 1
A development team is migrating a legacy application that stores passwords in plaintext. They want to choose a secure storage method that resists both offline brute-force and rainbow-table attacks. Which approach should they implement?
Select an answer first - 2
A security analyst notices a large number of failed login attempts against a legacy application that stores passwords as salted SHA-1 hashes. The analyst wants to detect whether the attacker has successfully cracked any hashes and respond quickly. Which action should the analyst take first?
Select an answer first - 3
A security operations center (SOC) analyst is reviewing logs and sees a pattern: a single user account has had 50 failed login attempts over 10 minutes, followed by a successful login from a foreign IP address. The analyst needs to respond immediately. What is the most appropriate first action?
Select an answer first - 4
A company is updating its password policy. The current policy requires 8 characters with complexity and forces a change every 90 days. The security team wants to align with current best practices. Which policy change is most aligned with modern recommendations?
Select an answer first - 5
A company's remote workers use a VPN that requires only a username and password. After a phishing campaign targeted these workers, management wants to add a second authentication factor without purchasing new hardware tokens. Which option is most practical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.