A system administrator wants to prevent password compromises from offline password attacks.
Which of the following controls should be configured to BEST accomplish this task? (Select TWO)
A.
Password reuse
B.
Password length
C.
Password complexity
D.
Password history
E.
Account lockouts
B and C.
B and C. “Offline” is the key word.
Need to consider a different thought here. If a password is compromised offline but you have effective password reuse policies, then the bad guy would find his/her work useless–because the password has been changed and the old password would not be used again. I think that complexity and length are probably correct for this question but a real case can be made for password reuse. It would prevent password compromises from offline password attack.
I would agree that it is B and C as well, although reuse is a good thought too. It cannot be account lockout due to the phrase “offline password attacks”