312-50V13 · Question #115
Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he…
The correct answer is A. Hardware, Software, and Sniffing. To retrieve passwords from client hosts and servers during a penetration test, a consultant would employ various methods including hardware keyloggers, software keyloggers, and network sniffing.
Question
Options
- AHardware, Software, and Sniffing.
- BHardware and Software Keyloggers.
- CPasswords are always best obtained using Hardware key loggers.
- DSoftware only, they are the most effective.
How the community answered
(21 responses)- A90% (19)
- B5% (1)
- D5% (1)
Why each option
To retrieve passwords from client hosts and servers during a penetration test, a consultant would employ various methods including hardware keyloggers, software keyloggers, and network sniffing.
Hardware keyloggers are physical devices that capture keystrokes, software keyloggers are programs that record user input, and network sniffing involves capturing network traffic to extract credentials. All three are viable and common methods used by penetration testers to obtain passwords depending on the target environment and access level.
While hardware and software keyloggers are effective, this option omits network sniffing, which is another crucial method for password retrieval in many scenarios.
This statement is false; passwords can be obtained through various means, and hardware keyloggers are not always the 'best' or most practical method in all situations, especially for remote systems.
This statement is false; software keyloggers are effective, but they are not the only nor always the most effective method, as hardware keyloggers and network sniffing also play significant roles in password retrieval.
Concept tested: Password retrieval techniques
Topics
Community Discussion
No community discussion yet for this question.