Mitigating Brute-Force Attacks: Password Policy Priority
A server administrator has been asked to implement a password policy that will help mitigate the chance of a successful brute-force attack. Which of the following password policies should the administrator implement first?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the prioritization of controls, where the common trap is selecting password complexity instead of recognizing that lockout directly stops the brute-force mechanism.
To effectively mitigate brute-force attacks, account lockout policies should be implemented first to halt repeated guessing attempts. Community consensus highlights that complexity is irrelevant without limiting the number of attempts available to an attacker.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Account lockout is the most direct defense against brute-force attacks because it limits the number of guesses an attacker can make before the account becomes temporarily or permanently inaccessible. Without a lockout mechanism, even a complex password can eventually be cracked if the attacker has unlimited time and resources to guess every combination.Why the Other Options Are Wrong
Password complexity (Option C) increases the entropy of the password but does not stop an automated script from trying millions of combinations per second; it only makes each individual attempt harder to succeed in isolation. Length (Option B) contributes to strength but suffers from the same issue as complexity without rate-limiting. Minimum age (Option D) prevents users from changing passwords too frequently, which is unrelated to preventing unauthorized access via guessing.Community Comment Notes
Comment [1] correctly argues that complexity is irrelevant if the attacker has infinite attempts, making lockout the necessary first step. Comment [2] acknowledges the difficulty of choosing one but agrees that lockout is the more critical immediate control for this specific threat vector.Exam Strategy
When asked to prioritize security controls, identify the control that directly addresses the root cause or mechanics of the specific attack mentioned. For brute-force, the mechanic is 'repeated attempts,' so look for controls that limit frequency or quantity.
Related Analysis
Practice All SK0-005 Questions
Access 135 questions with complete answers and detailed explanations.
View Full SK0-005 Practice Test →