A system administrator wants to prevent password compromises from offline password attacks. Which of the
following controls should be configured to BEST accomplish this task? (Choose two.)
A.
Password reuse
B.
Password length
C.
Password complexity
D.
Password history
E.
Account lockouts
A and D in my opinion.
it states “OFFLINE Password Attacks” and in that case, Account Lockouts would not matter since it will only take 1 try to login if you have broken the password OFFLINE.
thoughts?
The correct answers would be B and C. Because if the password attack is offline, the password reuse policy wouldn’t matter.
The password complexity and length would protect the account against the attack.