nerdexam
GIAC

GWAPT · Question #56

During a penetration test, you find that a web application does not implement account lockout policies. What is your next step?

The correct answer is A. Perform a brute-force attack to attempt logging in with common passwords. See the full explanation below for the reasoning.

Question

During a penetration test, you find that a web application does not implement account lockout policies. What is your next step?

Options

  • APerform a brute-force attack to attempt logging in with common passwords
  • BConduct SQL injection tests on the login form
  • CCheck for server uptime
  • DTest for cross-site scripting on the login page

How the community answered

(43 responses)
  • A
    70% (30)
  • B
    9% (4)
  • C
    5% (2)
  • D
    16% (7)

Community Discussion

No community discussion yet for this question.

Full GWAPT Practice