21 Questions
0 Views
3.5 Stars

Password Security and Authentication

Learn about password vulnerabilities and security techniques, including offline dictionary attacks, workstation hijacking, and exploiting user mistakes.

Created by
@NobleKrypton
1/21
Find out if you were right!
Create an account to continue playing and access all the benefits such as generating your own quizzes, flashcards and much more!
Quiz Team

Access to a Library of 520,000+ Quizzes & Flashcards

Explore diverse subjects like math, history, science, literature and more in our expanding catalog.

Questions and Answers

What is the primary purpose of using a salt value in password hashing?

To prevent duplicate passwords and make offline dictionary attacks more difficult

What is the main benefit of password hashing in terms of password security?

It prevents cybercriminals from getting access to the passwords file

What type of attack is made more difficult by the use of hashed passwords and salt values?

Offline dictionary attack

What is the primary function of the ID in discretionary access control?

<p>To determine the privileges accorded to the user</p> Signup and view all the answers

What is the purpose of designing a hash algorithm to be slow to execute?

<p>To thwart attacks</p> Signup and view all the answers

What is a common type of password vulnerability?

<p>Exploiting multiple password use</p> Signup and view all the answers

What is the primary purpose of using salt values in password hashing?

<p>To make precomputation impractical due to vast number of possible hash values</p> Signup and view all the answers

Why are shorter password lengths more susceptible to cracking?

<p>Because they have fewer possible combinations</p> Signup and view all the answers

What type of attack is an attacker planning when using a rainbow table?

<p>Rainbow table attack</p> Signup and view all the answers

What is the purpose of a password file access control?

<p>To deny access to encrypted passwords</p> Signup and view all the answers

What is the primary goal of proactive password checking?

<p>To eliminate guessable passwords while allowing users to select a memorable password</p> Signup and view all the answers

What type of authentication uses objects possessed by users for authentication purposes?

<p>Token-based authentication</p> Signup and view all the answers

What is a disadvantage of using SMS-based one-time passwords for authentication?

<p>It requires mobile coverage to receive SMS</p> Signup and view all the answers

What is a type of attack that involves intercepting messages using a fake mobile tower or attacking SS7 signaling protocol?

<p>Eavesdropping attack</p> Signup and view all the answers

What is a characteristic of mobile authentication apps?

<p>Implements a one-time password generator</p> Signup and view all the answers

What is a disadvantage of using biometric authentication?

<p>It is technically complex and expensive</p> Signup and view all the answers

What is a type of attack that involves an adversary attempting to learn a password by some sort of attack that involves physical proximity?

<p>Eavesdropping attack</p> Signup and view all the answers

What is a common defense against password guessing attacks?

<p>Hashing and protecting the password database</p> Signup and view all the answers

What is a type of attack that involves an adversary repeating a previously captured user response?

<p>Replay attack</p> Signup and view all the answers

What is a type of attack that involves an application or physical device masquerading as an authentic application or device?

<p>Trojan horse attack</p> Signup and view all the answers

What is a type of attack that involves an adversary attempting to disable a user authentication service by flooding the service with numerous authentication attempts?

<p>Denial-of-Service attack</p> Signup and view all the answers

Studying That Suits You

Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

Quiz Team

More Quizzes Like This

Use Quizgecko on...
Browser
Browser