exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 150 discussion

Actual exam question from CompTIA's SY0-601
Question #: 150
Topic #: 1
[All SY0-601 Questions]

A security policy states that common words should not be used as passwords. A security auditor was able to perform a dictionary attack against corporate credentials. Which of the following controls was being violated?

  • A. Password complexity
  • B. Password history
  • C. Password reuse
  • D. Password length
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rodwave
Highly Voted 2 years, 6 months ago
Selected Answer: A
Answer: Password complexity Password complexity is a measure of how difficult a password is to guess in relation to any number of guessing or cracking methods. For the security auditor to be able to successfully perform a dictionary attack, that means that the credentials were too predictable and was likely a common password.
upvoted 10 times
...
LordJaraxxus
Most Recent 1 year, 2 months ago
Selected Answer: A
It's true that a password length is more important than complexity, but in my guide from Darill Gibson there is no such thing as password length. It is mentioned but the complexity is the control that was violated
upvoted 1 times
...
7308365
1 year, 4 months ago
A. Password Complexity
upvoted 1 times
...
jack35567
1 year, 6 months ago
There is a strong argument for C but I’m sure that’s not it since 90% chose A. A dictionary attack can be a library of compromised passwords from other sites which users could use the same passwords across multiple accounts which would be a violation. But then again, restricting password reuse across multiple accounts from different platforms is likely not enforceable in most scenarios.
upvoted 1 times
...
Protract8593
1 year, 10 months ago
Selected Answer: A
The security policy states that common words should not be used as passwords, which implies that the passwords should have certain complexity requirements to avoid using easily guessable passwords. A dictionary attack is an attempt to crack passwords by systematically trying words from a dictionary, and it can be successful when passwords lack complexity. By enforcing password complexity requirements, organizations aim to prevent attackers from using simple and common words as passwords.
upvoted 1 times
...
tutita
2 years, 2 months ago
Selected Answer: A
we need more easy questions like this
upvoted 4 times
user82
2 years, 1 month ago
I wish 6% of voters agreed. This question still has people picking D
upvoted 1 times
...
...
xxxdolorxxx
2 years, 4 months ago
Selected Answer: A
A makes the most amount of sense to me.
upvoted 1 times
...
NICKJONRIPPER
2 years, 6 months ago
Selected Answer: C
passwords in common dictionary is not necessarily not complex. In the well-known "/usr/share/wordlists/rockyou.txt" dictionary, we can find passwords like "arisDAN13032008", "[email protected]"... So it`s about reuse, not about complexity.
upvoted 1 times
Sandon
2 years, 5 months ago
That ain't it
upvoted 6 times
...
...
Gino_Slim
2 years, 7 months ago
Selected Answer: A
Not even sure how that one person got D. The answer is A all the way. Complexity refers to how the password needs to be formatted.
upvoted 1 times
...
RonWonkers
2 years, 8 months ago
Selected Answer: A
It is A
upvoted 2 times
...
Ay_ma
2 years, 9 months ago
Selected Answer: D
According to guidance offered by the National Institute of Standards and Technology (NIST), password length is more important than password complexity. This actually makes a lot of sense as longer passphrases take longer to crack, and they are easier to remember than a string of meaningless characters. NIST has provided a number of additional recommendations for organizations to follow, some of which include: - Passphrases should consist of 15 or more characters. - Uppercase, lowercase, or special characters are not required. - Only ask users to change their passwords if you believe your network has been compromised. - Check all new passwords against a list of passwords that are frequently compromised. - Avoid locking your users out of their accounts after a number of unsuccessful login attempts, as hackers will often try to flood networks by purposely trying incorrect passwords in order to lock users out of their accounts. - Don’t allow password “hints.” www.lepide.com I'm inclined to go for option D
upvoted 1 times
RonWonkers
2 years, 8 months ago
This might be true but it does not answer the question. The question is: Which of the following controls was being violated? When using a standard word you violate complexity control.
upvoted 6 times
...
user82
2 years, 1 month ago
No WAY it’s D. Come on man. Complex passwords > password length
upvoted 1 times
...
rhocale
2 years, 5 months ago
this would make sense except the fact that its a dictionary account and length of words wont stop a dictionary account its still a basic word
upvoted 2 times
...
...
comeragh
2 years, 9 months ago
Selected Answer: A
Agree with A here
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...