nerdexam
CompTIA

PT0-003 · Question #66

A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the…

The correct answer is A. Credential stuffing. Credential stuffing uses known username-password pairs (often from previous breaches) and attempts to log in without guessing, reducing the risk of lockouts by limiting attempts per account.

Submitted by yaw92· Mar 6, 2026Attacks and Exploits

Question

A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the following techniques should the tester use?

Options

  • ACredential stuffing
  • BMFA fatigue
  • CDictionary attack
  • DBrute-force attack

How the community answered

(22 responses)
  • A
    73% (16)
  • B
    5% (1)
  • C
    9% (2)
  • D
    14% (3)

Explanation

Credential stuffing uses known username-password pairs (often from previous breaches) and attempts to log in without guessing, reducing the risk of lockouts by limiting attempts per account.

Topics

#credential stuffing#password attacks#account lockout policies

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice