nerdexam
EC-Council

312-50V9 · Question #563

Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he…

The correct answer is A. Hardware, Software, and Sniffing. Password retrieval during an assessment can leverage hardware keyloggers, software keyloggers, and network sniffing, making option A the most comprehensive and accurate answer.

System Hacking

Question

Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he is evaluating. Bob is familiar with password weaknesses and key loggers. Which of the following options best represents the means that Bob can adopt to retrieve passwords from his clients hosts and servers?

Options

  • AHardware, Software, and Sniffing.
  • BHardware and Software Keyloggers.
  • CPasswords are always best obtained using Hardware key loggers.
  • DSoftware only, they are the most effective.

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Password retrieval during an assessment can leverage hardware keyloggers, software keyloggers, and network sniffing, making option A the most comprehensive and accurate answer.

AHardware, Software, and Sniffing.Correct

Hardware keyloggers (physical devices attached to keyboards or USB ports), software keyloggers (malicious applications capturing keystrokes), and network sniffing (capturing cleartext credentials over the wire using tools like Wireshark) collectively represent the full spectrum of password retrieval techniques available to an assessor.

BHardware and Software Keyloggers.

Hardware and software keyloggers alone omit network sniffing, which is a distinct and highly effective method for capturing credentials transmitted in plaintext protocols like Telnet, FTP, or HTTP.

CPasswords are always best obtained using Hardware key loggers.

This overstates hardware keyloggers as always the best method; software keyloggers and sniffing are often more scalable and less detectable in enterprise environments.

DSoftware only, they are the most effective.

Limiting retrieval to software only ignores hardware keyloggers and sniffing, both of which are valid and commonly used password capture techniques.

Concept tested: Password retrieval techniques during security assessment

Source: https://owasp.org/www-community/attacks/Keystroke_Logging

Topics

#password retrieval#keyloggers#sniffing#password assessment

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice