CompTIA
PT0-003 · Question #66
A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the…
The correct answer is A. Credential stuffing. Credential stuffing uses known username-password pairs (often from previous breaches) and attempts to log in without guessing, reducing the risk of lockouts by limiting attempts per account.
Submitted by yaw92· Mar 6, 2026Attacks and Exploits
Question
A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the following techniques should the tester use?
Options
- ACredential stuffing
- BMFA fatigue
- CDictionary attack
- DBrute-force attack
How the community answered
(22 responses)- A73% (16)
- B5% (1)
- C9% (2)
- D14% (3)
Explanation
Credential stuffing uses known username-password pairs (often from previous breaches) and attempts to log in without guessing, reducing the risk of lockouts by limiting attempts per account.
Topics
#credential stuffing#password attacks#account lockout policies
Community Discussion
No community discussion yet for this question.