Study. uk . com
  1. Home
  2. All questions
  3. Question 458

CompTIA Security+ study material · question 458 of 611

An attacker steals a password hash file. Why does the login endpoint's rate limiting no longer help?

  1. Offline cracking runs at the attacker's own pace, away from the login endpoint
  2. Hashes are not covered by rate limiting policy
  3. The attacker can disable the rate limiter
  4. Rate limiting resets when hashes are exported
Show the answer

Answer: A. Offline cracking runs at the attacker's own pace, away from the login endpoint

Throttling protects the online path; only a slow, salted hash raises the cost of the offline attack.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › When Password Hashes Can Be Cracked

Challenge yourself on this topic → Study as cards