312-50V9 · Question #563
Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he…
The correct answer is A. Hardware, Software, and Sniffing. Password retrieval during an assessment can leverage hardware keyloggers, software keyloggers, and network sniffing, making option A the most comprehensive and accurate answer.
Question
Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he is evaluating. Bob is familiar with password weaknesses and key loggers. Which of the following options best represents the means that Bob can adopt to retrieve passwords from his clients hosts and servers?
Options
- AHardware, Software, and Sniffing.
- BHardware and Software Keyloggers.
- CPasswords are always best obtained using Hardware key loggers.
- DSoftware only, they are the most effective.
How the community answered
(41 responses)- A90% (37)
- B5% (2)
- C2% (1)
- D2% (1)
Why each option
Password retrieval during an assessment can leverage hardware keyloggers, software keyloggers, and network sniffing, making option A the most comprehensive and accurate answer.
Hardware keyloggers (physical devices attached to keyboards or USB ports), software keyloggers (malicious applications capturing keystrokes), and network sniffing (capturing cleartext credentials over the wire using tools like Wireshark) collectively represent the full spectrum of password retrieval techniques available to an assessor.
Hardware and software keyloggers alone omit network sniffing, which is a distinct and highly effective method for capturing credentials transmitted in plaintext protocols like Telnet, FTP, or HTTP.
This overstates hardware keyloggers as always the best method; software keyloggers and sniffing are often more scalable and less detectable in enterprise environments.
Limiting retrieval to software only ignores hardware keyloggers and sniffing, both of which are valid and commonly used password capture techniques.
Concept tested: Password retrieval techniques during security assessment
Source: https://owasp.org/www-community/attacks/Keystroke_Logging
Topics
Community Discussion
No community discussion yet for this question.