GIAC
GWAPT · Question #56
During a penetration test, you find that a web application does not implement account lockout policies. What is your next step?
The correct answer is A. Perform a brute-force attack to attempt logging in with common passwords. See the full explanation below for the reasoning.
Question
During a penetration test, you find that a web application does not implement account lockout policies. What is your next step?
Options
- APerform a brute-force attack to attempt logging in with common passwords
- BConduct SQL injection tests on the login form
- CCheck for server uptime
- DTest for cross-site scripting on the login page
How the community answered
(43 responses)- A70% (30)
- B9% (4)
- C5% (2)
- D16% (7)
Community Discussion
No community discussion yet for this question.