Refer to the exhibit. An attacker is attempting to guess passwords against a Linux service. Why does this lockout mechanism fail to prevent a distributed brute-force attack?
Exhibit
LOG_ENTRY: user 'admin' failed login 5 times. Status: 0x4002. Policy: Lockout after 3 attempts. Action: Account locked.
Trap 1: The service uses SHA-256 for password storage
The hashing algorithm determines how fast a password can be cracked offline, not how many online login attempts are allowed. Even with strong hashing, an online brute-force attempt is limited by account lockout thresholds. The lockout mechanism failing is due to architecture, not the strength of the hash.
Trap 2: The system clock is not synchronized
System clock synchronization is vital for log correlation and Kerberos authentication, but it does not influence the logic of an account lockout policy. Lockout mechanisms are based on incrementing counters in the authentication database, which function correctly regardless of the server's time compared to external network time.
Trap 3: The error code 0x4002 indicates a buffer overflow
Error code 0x4002 in this context is defined by the security policy as an account lockout state. It does not signify a memory corruption exploit or buffer overflow vulnerability. The failure to stop the attack is due to the logic of the lockout policy, not an underlying software exploit.
- A
The service uses SHA-256 for password storage
Why it fails: The hashing algorithm determines how fast a password can be cracked offline, not how many online login attempts are allowed. Even with strong hashing, an online brute-force attempt is limited by account lockout thresholds. The lockout mechanism failing is due to architecture, not the strength of the hash.
- B
The attacker is using a distributed botnet
Distributed brute-force attacks use large botnets to spread attempts across many accounts and multiple source IPs. By only hitting each account once or twice, the attacker stays below the lockout threshold while collectively performing thousands of attempts. This makes account-specific lockouts ineffective against modern, high-volume automated credential stuffing.
- C
The system clock is not synchronized
Why it fails: System clock synchronization is vital for log correlation and Kerberos authentication, but it does not influence the logic of an account lockout policy. Lockout mechanisms are based on incrementing counters in the authentication database, which function correctly regardless of the server's time compared to external network time.
- D
The error code 0x4002 indicates a buffer overflow
Why it fails: Error code 0x4002 in this context is defined by the security policy as an account lockout state. It does not signify a memory corruption exploit or buffer overflow vulnerability. The failure to stop the attack is due to the logic of the lockout policy, not an underlying software exploit.