GIAC Security Essentials GSEC Question # 87 Topic 9 Discussion

GIAC Security Essentials GSEC Question # 87 Topic 9 Discussion

GSEC Exam Topic 9 Question 87 Discussion:
Question #: 87
Topic #: 9

You ask your system administrator to verify user compliance with the corporate policies on password strength, namely that all passwords will have at least one numeral, at least one letter, at least one special character and be 15 characters long. He comes to you with a set of compliance tests for use with an offline password cracker. They are designed to examine the following parameters of the password:

* they contain only numerals

* they contain only letters

* they contain only special characters

* they contain only letters and numerals

" they contain only letters and special characters

* they contain only numerals and special characters

Of the following, what is the benefit to using this set of tests?


A.

They are focused on cracking passwords that use characters prohibited by the password policy


B.

They find non-compliant passwords without cracking compliant passwords.


C.

They are focused on cracking passwords that meet minimum complexity requirements


D.

They crack compliant and non-compliant passwords to determine whether the current policy is strong enough


Get Premium GSEC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.