exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 222 discussion

Actual exam question from CompTIA's PT0-002
Question #: 222
Topic #: 1
[All PT0-002 Questions]

During an assessment, a penetration tester obtains a list of 30 email addresses by crawling the target company's website and then creates a list of possible usernames based on the email address format. Which of the following types of attacks would MOST likely be used to avoid account lockout?

  • A. Mask
  • B. Rainbow
  • C. Dictionary
  • D. Password spraying
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sborrainculo
Highly Voted 2 years, 5 months ago
Selected Answer: D
It is indeed password spraying. Trying the same passwords across multiple users.
upvoted 6 times
...
Etc_Shadow28000
Most Recent 11 months, 1 week ago
Selected Answer: D
D. Password spraying Explanation: Password spraying: • Password spraying is an attack where the attacker tries a small number of common passwords against a large number of accounts. This method helps avoid account lockout mechanisms because it doesn’t repeatedly target the same account with multiple password attempts. Instead, it uses a common password across many accounts, thereby staying under the threshold that triggers account lockouts.
upvoted 1 times
Etc_Shadow28000
11 months, 1 week ago
C. Dictionary: • Dictionary attacks involve using a predefined list of potential passwords (a dictionary) to guess passwords. Like mask attacks, if multiple attempts are made on the same account, this can trigger account lockout mechanisms.
upvoted 1 times
...
...
pepgua
1 year ago
The MOST likely attack type to avoid account lockout, given the information, is: D. Password spraying Password spraying involves trying a large number of password guesses against a list of usernames. In this case, the penetration tester has a list of email addresses and can create usernames based on the format. They can then use password spraying to try a set of common passwords (or variations) against each username.
upvoted 1 times
...
solutionz
1 year, 10 months ago
Selected Answer: D
Password spraying is a type of attack where the attacker attempts to access a large number of accounts (usernames) using a few common passwords. Unlike traditional brute-force or dictionary attacks, which try many passwords on a single user, password spraying tries only a few passwords across many accounts. This method is often used to avoid triggering account lockout mechanisms, making it a suitable choice for the scenario described.
upvoted 2 times
...
nickwen007
2 years, 3 months ago
D. Password spraying is the most likely attack that would be used to avoid account lockout during an assessment. This technique involves using a list of commonly used passwords to try guess a user's password by making multiple attempts at a single user account. It is important to practice good online safety habits, such as strong password creation and monitoring of accounts, to prevent this type of attack.
upvoted 2 times
...
cy_analyst
2 years, 3 months ago
Selected Answer: D
Password spraying is trying a small number of passwords against a large number of accounts, rather than trying many passwords against a single account. Dictionary attacks involve trying a large number of words from a dictionary file as possible passwords. Mask attacks are used when an attacker has some information about the password, such as its length or character set, and wants to generate a list of possible passwords based on that information.
upvoted 2 times
[Removed]
2 years, 3 months ago
Wha you think about question 78?
upvoted 1 times
...
...
beamage
2 years, 3 months ago
Selected Answer: D
https://www.crowdstrike.com/cybersecurity-101/password-spraying/#:~:text=The%20basics%20of%20a%20password,account%20by%20trying%20many%20passwords.
upvoted 2 times
...
kloug
2 years, 3 months ago
d answer
upvoted 2 times
...
Afhenfxsv
2 years, 5 months ago
Selected Answer: D
the answer is D
upvoted 4 times
...
masso435
2 years, 6 months ago
Selected Answer: D
Dictionary attacks are used more in offline situations.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...