Lockout Observation Window refers to:

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

Lockout Observation Window refers to:

Explanation:
Lockout observation window is the period during which failed logon attempts are counted toward the lockout threshold. If the threshold is met or exceeded within this window, the account is locked; once the window passes, the count resets and new failures start fresh. For example, with a policy of 5 failed attempts within 15 minutes, five consecutive failures within that 15-minute span will lock the account. If more than 15 minutes pass since the first failure, the counter resets, and subsequent failures no longer count toward the previous window. The other ideas describe different concepts: how long a locked account remains disabled, auditing during specific times, or password history checks during changes, none of which govern how failed attempts are aggregated over time.

Lockout observation window is the period during which failed logon attempts are counted toward the lockout threshold. If the threshold is met or exceeded within this window, the account is locked; once the window passes, the count resets and new failures start fresh.

For example, with a policy of 5 failed attempts within 15 minutes, five consecutive failures within that 15-minute span will lock the account. If more than 15 minutes pass since the first failure, the counter resets, and subsequent failures no longer count toward the previous window.

The other ideas describe different concepts: how long a locked account remains disabled, auditing during specific times, or password history checks during changes, none of which govern how failed attempts are aggregated over time.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy