
EC-CouncilEthical Hacking Essentials
Domain 2Objective 5
Password Cracking Countermeasures EHE Practice Questions (Page 6)
Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.
44questions here
9free pages
7concepts
Questions 26–30
- 26
A security analyst notices a spike in failed login attempts against a single user account from many different IP addresses over a short period. The account has MFA enabled. What should the analyst do first?
Select an answer first - 27
How does rate limiting help defend against password cracking attempts?
Select an answer first - 28
A security analyst is investigating a possible password hash leak. The analyst finds that the attacker downloaded the hash database but has not yet logged in. The database contains salted SHA-256 hashes. The analyst must decide whether to force a mass password reset. Which consideration is most important in this decision?
Select an answer first - 29
What is the primary purpose of implementing password cracking countermeasures in an organization?
Select an answer first - 30
An organization discovers that many employees reuse the same password across personal and corporate accounts. The security team wants to reduce the risk of credential stuffing without forcing users to memorize dozens of unique passwords. Which measure is the most effective first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.