CompTIA PBQ Practice Question - Password Policies - Security+, CySA+, CASP+ Network+

Поділитися
Вставка
  • Опубліковано 28 гру 2024

КОМЕНТАРІ • 19

  • @derekarmstrong1408
    @derekarmstrong1408 4 місяці тому +5

    You're the 10th or 11th UA-camr I've followed, and the most easy to follow along with. You're doing a great job of demystifying this stuff. Thank you.

  • @AJ-pq9mn
    @AJ-pq9mn 4 місяці тому +4

    Thank you for your videos, I passed my sec+ 701 today thanks to some of your PBQ’s.

  • @cristianyepez1507
    @cristianyepez1507 4 місяці тому +2

    On my way to take the sec+ exam!

    • @cyberkraft1
      @cyberkraft1  4 місяці тому

      Good luck!

    • @cristianyepez1507
      @cristianyepez1507 4 місяці тому

      @@cyberkraft1 passed!!! Thank you so muchhh

    • @MLH8789
      @MLH8789 3 місяці тому

      @@cristianyepez1507 Congrats! Taking mine in 3 weeks!

    • @cristianyepez1507
      @cristianyepez1507 3 місяці тому

      @@MLH8789 you got this!! Mine had a lot of acronyms

  • @VinTagebeats
    @VinTagebeats 3 місяці тому

    Thank you for this !

  • @ironsilk6634
    @ironsilk6634 5 місяців тому +1

    Good 1 bro

  • @zrproductions6469
    @zrproductions6469 2 місяці тому

    For the first question, wouldn’t passwords one and two be swapped because password 1 contains a common phrase while password two has a bunch of random characters despite being a bit shorter and not starting with a special character?

    • @austinhorton7074
      @austinhorton7074 9 днів тому

      that's what I thought, too because that would be an easy pw to hack

  • @RockMusicFanNo1
    @RockMusicFanNo1 5 місяців тому +1

    I disagree with the false option (SMS OTP). Sim swapping is incredibly difficult as of 2024, unless you are a high ranking person in the organization or political landscape. For 99% of employees, SMS OTP should be fine. Similarly, it might be the only non costly method to provide free 2FA to a user, as most TOTP software is offered for free when you have already purchased or paid for paid solutions or services.
    Is SMS 2FA bad, and if so, should banks up their game in their customers’ account security and abolish it?

    • @williamh7
      @williamh7 5 місяців тому +2

      Some phone carriers, still allow user verification with last four of social security number. For some reason they won't change the policy and basically all of our socials, names, addresses have been leaked by multiple companies. Also, a bad phone carrier employee can easily do malicious activities.

    • @RG_spc
      @RG_spc 5 місяців тому +1

      Bank example is for public hence very difficult to have all install authenticator app. That's done easily with employees, which is the exact use-case here.
      Nothing is probably 100% secure all the time for all cases. However, on balance of factors, I tend to agree with the authors of the video. From multiple experiences, employers commonly use Authenticators (Google, Microsoft, some even their own), whereas Banks use SMS. Is there a risk with banks using SMS? Yes. How do they address it? Multiple ways. Some banks also send email, some may even call up on suspected transactions (and ask security questions). That ssid, I've also seen banks use TOTP through their own mobile apps.

    • @ancleasai
      @ancleasai 5 місяців тому

      SMS is vulnerable to SS7 attacks and it's use is deprecated in place of more secure alternatives. Sending SMS though low cost is not free

    • @Euruzilys
      @Euruzilys 4 місяці тому

      Singapore announced a ban on using SMS OTP for banking app. And if I remember correctly, Malaysia also has it banned too. So SMS OTP being considered insecure here is probably the right choice, and an up to date. Still, this is a CompTIA exam, so it’s gonna depend on them.

  • @SamadAli-rf1un
    @SamadAli-rf1un 5 місяців тому +1

    Hi Dennis thanks for the PBQ content related to password policies for Security+ exams, currently I have security+ certification, and would like to know what is the difference between CompTIA Security+ and CompTIA SecurityX.

    • @cyberkraft1
      @cyberkraft1  5 місяців тому +1

      The SecurityX is the new version of the CompTIA CASP+.

    • @SamadAli-rf1un
      @SamadAli-rf1un 5 місяців тому

      @@cyberkraft1 Thanks :)