- Home
- All questions
- Question 458
CompTIA Security+ study material · question 458 of 611
An attacker steals a password hash file. Why does the login endpoint's rate limiting no longer help?
Show the answer
Answer: A. Offline cracking runs at the attacker's own pace, away from the login endpoint
Throttling protects the online path; only a slow, salted hash raises the cost of the offline attack.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › When Password Hashes Can Be Cracked