A city login portal has no lockout. The tester must choose a password-attack approach that still respects careful RoE. Which judgment is soundest?
Select an answer to reveal the explanation.
Short Explanation
Spraying is like trying the same two keys on many locks; brute force is grinding one lock with every key you own. Even without lockout, the spray-style mindset keeps noise and account pain lower. Respect the RoE and pick the gentler pattern.
Full Explanation
Password spraying tests a small set of common passwords across many accounts, while dense brute force concentrates many guesses on one identity. Even when lockout is missing, spray-class pacing and breadth usually align better with availability and detection constraints in Rules of Engagement. Unbounded online brute force against production portals risks service disruption and noisy authentication failures. Choosing the attack class is a judgment call about safety and authorization, not only about likelihood of a hit.