nerdexam
CompTIA

PT0-002 · Question #545

Given the following finding: Which of the following recommendations should a penetration tester make?

The correct answer is B. Improving the account lockout policy. The penetration tester used a brute-force attack to guess the password for the RDP service. The fact that the attack succeeded suggests the system does not have an effective account lockout policy in place. An account lockout policy would help to mitigate such brute-force…

Reporting and Communication

Question

Given the following finding:

Which of the following recommendations should a penetration tester make?

Exhibit

PT0-002 question #545 exhibit

Options

  • AEncrypting passwords
  • BImproving the account lockout policy
  • CSanitizing user input
  • DImplementing time-of-day restrictions

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    71% (30)
  • C
    17% (7)
  • D
    7% (3)

Explanation

The penetration tester used a brute-force attack to guess the password for the RDP service. The fact that the attack succeeded suggests the system does not have an effective account lockout policy in place. An account lockout policy would help to mitigate such brute-force attacks by locking an account after a certain number of failed login attempts, making it more difficult for an attacker to guess the password.

Topics

#Account lockout policy#Brute-force protection#Security recommendations

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice