A city Active Directory policy allows short passwords. What impact should the assessment highlight?
Select an answer to reveal the explanation.
Short Explanation
Short passwords are like flimsy bike locks—fine until someone actually tries. Weak policy makes guessing and cracking far more realistic once hashes or login surfaces are in play. Policy is part of the attack surface, not just an IT preference.
Full Explanation
Directory password policy governs minimum length and complexity for many accounts simultaneously. Weak settings increase the success rate of online guessing within RoE limits and make offline cracking more feasible if password hashes are obtained elsewhere in the engagement. Highlighting policy weakness connects technical attack outcomes to a root cause the city can remediate centrally. Stronger baselines and complementary controls such as MFA reduce reliance on password strength alone.