Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 2Objective 5

Password Cracking Countermeasures EHE Practice Questions (Page 9)

Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.

44questions here
9free pages
7concepts

Questions 41–44

  1. 41expert · hard

    A company is updating its password policy. The security team wants to maximize resistance to offline cracking while minimizing user frustration and help-desk calls. The current policy requires 8-character passwords changed every 60 days. Which policy change best meets these competing goals?

    Select an answer first
  2. 42foundation · easy

    Which password policy requirement most directly increases the time needed for a brute-force attack to succeed?

    Select an answer first
  3. 43foundation · easy

    Which combination of practices represents the most effective general defense against password cracking attacks?

    Select an answer first
  4. 44application · medium

    A security auditor finds that a legacy application stores passwords as unsalted MD5 hashes. The auditor must recommend a remediation that balances security improvement with the need to keep the application running. Which recommendation is the best first step?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to EHE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.