A company wants to implement account lockout to prevent brute-force attacks. Which lockout threshold is most appropriate according to common best practices?
Trap 1: 1 failed attempt
Too strict; likely to lock out legitimate users.
Trap 2: No lockout, only logging
Logging alone does not prevent brute-force attacks.
Trap 3: 20 failed attempts
Too high; allows many brute-force guesses.
- A
5 failed attempts
A threshold of five failed attempts locks the account before an attacker can complete a practical brute-force run, while still tolerating ordinary mistyped passwords. This satisfies the stated goal of preventing brute-force attacks without generating excessive lockouts for legitimate users.
- B
1 failed attempt
Why it fails: Too strict; likely to lock out legitimate users.
- C
No lockout, only logging
Why it fails: Logging alone does not prevent brute-force attacks.
- D
20 failed attempts
Why it fails: Too high; allows many brute-force guesses.