CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 172: CAS-004: CompTIA Advanced Security Practitioner (CASP+) CAS-004

A security analyst is evaluating the security of an online customer banking system. The analyst has a 12-character password for the test account. At the login screen, the analyst is asked to enter the third, eighth, and eleventh characters of the password. Which of the following describes why this request is a securit…

Nội dung câu hỏi

A security analyst is evaluating the security of an online customer banking system. The analyst has a 12-character password for the test account. At the login screen, the analyst is asked to enter the third, eighth, and eleventh characters of the password. Which of the following describes why this request is a security concern? (Choose two.)

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. The request is evidence that the password is more open to being captured via a keylogger.
  2. B. The request proves that salt has not been added to the password hash, thus making it vulnerable to rainbow tables.
  3. C. The request proves the password is encoded rather than encrypted and thus less secure as it can be easily reversed.
  4. D. The request proves a potential attacker only needs to be able to guess or brute force three characters rather than 12 characters of the password. — đáp án hiện tại
  5. E. The request proves the password is stored in a reversible format, making it readable by anyone at the bank who is given access. — đáp án hiện tại
  6. F. The request proves the password must be in cleartext during transit, making it open to on-path attacks.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề