ITPEC IP October 2021 Question 42

Source exam: ITPEC IP October 2021Topic: Security

ITPEC IP October 2021 — Question 42 of 100

The second site is vulnerable because the user reused the same ID and password on both websites. A password-list attack takes credentials leaked from one service and automatically tries them on other services, succeeding when credentials have been reused.

Answer (b)

Why not others:
- unencrypted transmission is a separate interception risk and is not required for credential stuffing

- limited character variety and short length make guessing easier but do not explain reuse of a leaked credential pair on another site

Key rule: Use a unique password for every service so a breach of one site cannot directly compromise accounts elsewhere.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.