Password Cracking
Password cracking is the process of attempting to discover passwords through guessing, computation, or analysis of stored password data.
“A security attack recovering secret passwords stored in a computer system or transmitted over a network.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Password Cracking?
Security professionals use password cracking techniques during authorized assessments to evaluate password strength and identify weak authentication practices.
Attack techniques: Methods include brute force, dictionary attacks, and rainbow tables.
Security purpose: Authorized testing helps improve password policies.
Defense: Strong passwords and multi-factor authentication reduce risks.
Real World Example
A regulated product team is preparing a release where Password cracking appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Password cracking as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Password cracking and similar ideas.
The page becomes useful in practice because Password cracking is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which statement BEST describes Password cracking in the context of ISTQB terminology?
Question 2
A tester needs to explain Password cracking to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Password Cracking. Test your understanding with topic-specific questions in our Mock Exams.