4.2 Exercise 2: Password Policy Advisor

🎯 Before You Start

Exercise 1 trained you to name the attack. Exercise 2 asks you to stop it. Aceshack’s security lead has to turn each threat into specific login settings — minimum length, complexity, maximum password age, password history and account lockout (EK 4.2.D.1–D.5) — and defend the choice by mechanism. Expect tougher distractors: several options are real security improvements that simply do not touch the attack in the stem.

Strategy: read the stem, decide online or offline, and predict your own answer before you look at the options. A setting that only lives on the sign-in screen cannot slow an attacker who already holds a copy of the password file.

✎ Password Policy Advisor — 4 Questions
Question 1 of 4 — Multi-Select: What Survives an Offline Attack A backup of Aceshack’s credential store was copied off a decommissioned server and offered for sale. Every record in it is a salted hash. The attacker now runs cracking software against that file on hardware they own. Aceshack’s security lead proposes the four changes below for the accounts in that file. Which of them would raise the cost of this attacker’s work? Decide which settings can possibly matter here before you read the list. Select ALL that apply. No credit for selecting incorrect options.
Question 2 of 4 — Spot the Error in the Policy Draft Aceshack’s drop-in workstation signs remote workers into a portal reachable from the public internet. Overnight the portal absorbed thousands of failed sign-in attempts. A junior administrator drafted the local security policy below in answer to that threat. Exactly one row is wrong. Which row, and why?
ACESHACK SIGN-IN PORTAL — LOCAL SECURITY POLICY (DRAFT)
Row 1  Minimum password length ....... 14 characters
Row 2  Complexity requirement ........ 3 of the 4 character sets
Row 3  Account lockout threshold ..... disabled (staff complained about lockouts)
Row 4  Password history .............. last 10 passwords remembered
Row 5  Stored credential format ...... salted hash, unique salt per account
Question 3 of 4 — One Change, Two Findings Aceshack adds six more drop-in workstations. An audit returns two findings: (1) every new workstation is still running the vendor’s factory default administrator account and password, which are printed in the public setup guide; and (2) when the current 60-day rotation forces a change, most staff alternate between the same two passwords. Which single change addresses both findings?
Question 4 of 4 — Which Control Does the LEAST Over one weekend Aceshack’s portal logged 1,900 failed sign-ins from a single source address against 630 distinct accounts. No account was tried more than three times, the lockout threshold is set at five, and there was no successful sign-in. Which of the following would do the LEAST to reduce the risk from this campaign?
0 / 4 Questions correct — review any incorrect answers above, then move on to the Lab.
🚀 Extension Challenge

Configure it for real. Open the local security policy editor on a computer you own (on Windows, Account Policies inside the Local Security Policy tool) and write down the five settings from EK 4.2.D as they are configured right now: minimum length, complexity, maximum password age, password history and account lockout threshold. Then, in 3–5 sentences, name one attack from Lesson 4.2 that this configuration would not slow down, give the one setting you would change first, and explain the mechanism that makes your change work.

Naming the attack, naming the setting and explaining the mechanism is exactly the three-part structure AP Cyber FRQ-style scenario questions expect. Practicing it now pays off on exam day.

AP Cybersecurity · Unit 4 · Lesson 4.2 · Exercise 2
LessonExercise 1Exercise 2Quiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]