PT0-002 · Question #545
Given the following finding: Which of the following recommendations should a penetration tester make?
The correct answer is B. Improving the account lockout policy. The penetration tester used a brute-force attack to guess the password for the RDP service. The fact that the attack succeeded suggests the system does not have an effective account lockout policy in place. An account lockout policy would help to mitigate such brute-force…
Question
Given the following finding:
Which of the following recommendations should a penetration tester make?
Exhibit
Options
- AEncrypting passwords
- BImproving the account lockout policy
- CSanitizing user input
- DImplementing time-of-day restrictions
How the community answered
(42 responses)- A5% (2)
- B71% (30)
- C17% (7)
- D7% (3)
Explanation
The penetration tester used a brute-force attack to guess the password for the RDP service. The fact that the attack succeeded suggests the system does not have an effective account lockout policy in place. An account lockout policy would help to mitigate such brute-force attacks by locking an account after a certain number of failed login attempts, making it more difficult for an attacker to guess the password.
Topics
Community Discussion
No community discussion yet for this question.
