Mitigating Brute-Force Attacks: Password Policy Priority

A server administrator has been asked to implement a password policy that will help mitigate the chance of a successful brute-force attack. Which of the following password policies should the administrator implement first?

  1. Lockout Source Reference Answer
  2. Length
  3. Complexity
  4. Minimum age

Community Votes

A
67%
C
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the prioritization of controls, where the common trap is selecting password complexity instead of recognizing that lockout directly stops the brute-force mechanism.

To effectively mitigate brute-force attacks, account lockout policies should be implemented first to halt repeated guessing attempts. Community consensus highlights that complexity is irrelevant without limiting the number of attempts available to an attacker.

Community Discussion (5 comments)

Fakecon 👍 1
Both would be amazing lockout and complexity, and choosing only one makes this wrong answer. But since I can choose only one I would go with lockout.
surfuganda 👍 3 Selected: A
A. Lockout Password complexity is irrelevant if the attacker has infinite attempts to guess the password (brute force). A lockout policy will allow only a specified number of attempts before the account is disabled, which stops the attack.
AzadOB 👍 1 Selected: C
Complexity
RBL23168 👍 1 Selected: A
A. Lockout locking out accounts after a certain number of failed login attempts
AzadOB 👍 1 Selected: C
Complexity

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Account lockout is the most direct defense against brute-force attacks because it limits the number of guesses an attacker can make before the account becomes temporarily or permanently inaccessible. Without a lockout mechanism, even a complex password can eventually be cracked if the attacker has unlimited time and resources to guess every combination.

Why the Other Options Are Wrong

Password complexity (Option C) increases the entropy of the password but does not stop an automated script from trying millions of combinations per second; it only makes each individual attempt harder to succeed in isolation. Length (Option B) contributes to strength but suffers from the same issue as complexity without rate-limiting. Minimum age (Option D) prevents users from changing passwords too frequently, which is unrelated to preventing unauthorized access via guessing.

Community Comment Notes

Comment [1] correctly argues that complexity is irrelevant if the attacker has infinite attempts, making lockout the necessary first step. Comment [2] acknowledges the difficulty of choosing one but agrees that lockout is the more critical immediate control for this specific threat vector.

Exam Strategy

When asked to prioritize security controls, identify the control that directly addresses the root cause or mechanics of the specific attack mentioned. For brute-force, the mechanic is 'repeated attempts,' so look for controls that limit frequency or quantity.

Related Analysis

Practice All SK0-005 Questions

Access 135 questions with complete answers and detailed explanations.

View Full SK0-005 Practice Test →

← Back to SK0-005 Study Guide