When reporting password cracking activities, which metric should be documented for each account to help assess timing against policy?

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

When reporting password cracking activities, which metric should be documented for each account to help assess timing against policy?

Explanation:
The key idea is to capture the actual time it takes to crack each account. Recording the time to crack provides a direct, comparable measure of how quickly a password could be compromised under the tested conditions, which you can then map against the organization’s password policy and defense thresholds (like required complexity, length, and lockout timing). This helps you assess whether the policy slows attackers enough and where gaps might exist. Why the other possibilities aren’t as useful for this purpose: attacker name isn’t a metric of cracking performance or policy effectiveness, password length varies by account and isn’t a timing metric, and network path describes connectivity rather than the effort or speed of cracking.

The key idea is to capture the actual time it takes to crack each account. Recording the time to crack provides a direct, comparable measure of how quickly a password could be compromised under the tested conditions, which you can then map against the organization’s password policy and defense thresholds (like required complexity, length, and lockout timing). This helps you assess whether the policy slows attackers enough and where gaps might exist.

Why the other possibilities aren’t as useful for this purpose: attacker name isn’t a metric of cracking performance or policy effectiveness, password length varies by account and isn’t a timing metric, and network path describes connectivity rather than the effort or speed of cracking.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy