A security engineer is reviewing web application login telemetry after a series of credential-stuffing incidents. Management wants to minimize the chance that automated tools can rapidly guess user passwords while still limiting user frustration when typos occur. Which password-policy control would BEST slow an online brute-force attack in this environment?
Enforcing password complexity requirements with minimum length and special characters
Monitoring failed login attempts in system logs
Requiring password changes every 90 days
Implementing credential lockout mechanisms with increasing delays between attempts
Implementing credential lockout mechanisms that impose an exponentially increasing delay after each unsuccessful attempt directly throttles the rate at which an attacker can submit guesses. This control turns what would otherwise be millions of guesses per minute into only a handful per hour, making online brute-force attacks impractical. Complexity rules enlarge the keyspace but do not slow submission speed; expiration policies address compromised credentials, not guessing; and log monitoring merely detects activity after it occurs rather than preventing it.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why are credential lockout mechanisms effective against brute force attacks?
Open an interactive chat with Bash
How do password complexity requirements help against brute force attacks?
Open an interactive chat with Bash
What is the difference between preventive and detective controls in this context?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .