Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 2Objective 5

Password Cracking Countermeasures EHE Practice Questions (Page 3)

Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.

44questions here
9free pages
7concepts

Questions 11–15

  1. 11expert · hard

    A company's authentication database was breached, and attackers obtained password hashes. The hashes were generated with bcrypt using a cost factor of 4 and no salt. The security team is evaluating the damage. Which statement is most accurate?

    Select an answer first
  2. 12application · medium

    A development team is building a new web application and wants to store user passwords securely. The compliance team requires that passwords be resistant to offline cracking even if the database is leaked. Which storage approach should the team use?

    Select an answer first
  3. 13foundation · easy

    Why is it important to add a unique salt to each password before hashing?

    Select an answer first
  4. 14expert · hard

    A security analyst is reviewing logs and notices that a single user account has had 500 failed logon attempts over the past hour, followed by a successful logon. The account has MFA enabled, and the successful logon was completed with a valid MFA code. What is the most likely explanation?

    Select an answer first
  5. 15foundation · easy

    What is the purpose of auditing password-related events in an organization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.