PTE Academic · Summarize Written Text

Digital Authentication and Password Security

3 original Summarize Written Text questions. Question 1 is free to answer and check right here; log in free to practise the rest in the BandLadder app.
  • 3 questions
  • Question 1 free, no login
  • PTE Academic (PTE Core has its own version)
1

Cryptographic Password Hashing

Free to try, no login

Read the passage below and summarize it using one sentence. You have 10 minutes, and your response should be between 5 and 75 words.

When users register credentials on digital platforms, modern security architectures avoid storing plaintext strings within authentication databases. Instead, systems route incoming character sequences through cryptographic hash functions. These mathematical algorithms convert arbitrary text into unique, fixed-length values known as digests. Because these functions operate strictly unidirectionally, reconstructing the original secret phrase from its resulting digest is computationally infeasible under standard operating conditions.

Nevertheless, basic hashing remains susceptible to precomputed dictionary assaults, such as rainbow table attacks, in which adversaries cross-reference stolen digests against massive repositories of predetermined calculations. If multiple individuals select identical passwords, their stored hashes match perfectly, allowing an attacker to compromise numerous accounts simultaneously once a single match is established.

To counteract this vulnerability, security engineers implement cryptographic salting alongside iterated hashing. A salt is an unpredictable, uniquely generated character sequence appended to each plaintext input before mathematical processing begins. Consequently, two identical passwords produce entirely distinct digests within the database. This mechanism neutralises precomputed lookup tables and obliges adversaries to calculate hashes individually for every target, dramatically escalating the temporal and computational costs of offline breach analysis.

0 words · target 5–75, one sentence · 10 minutes in the test · spell-check is off, as in the test

Questions 2–3

Read the passage below and summarize it using one sentence. You have 10 minutes, and your response should be between 5 and 75 words.

Read them here; log in to answer and check them.

2

Passphrase Entropy and Diceware

For decades, standard digital authentication guidelines mandated the creation of short, highly complex passwords composed of uppercase letters, numbers, and obscure typographical symbols. However, cognitive studies and information theory demonstrate that these requirements frequently undermine genuine system protection. When compelled to devise convoluted combinations, human users predictably adopt minor variations of familiar terms or record their credentials insecurely. Furthermore, modern computational algorithms can crack short strings in fractions of a second, irrespective of character diversity.

In response to these vulnerabilities, cryptographers have increasingly advocated multi-word passphrases generated through structured randomisation frameworks, such as the Diceware method. Under this protocol, physical dice rolls or hardware random-number generators select words from a standardised, numbered lexicon. Because each chosen word contributes a calculable quantity of mathematical entropy, combining several unrelated vocabulary items creates an astronomical search space for potential attackers.

The fundamental strength of this paradigm lies in reconciling human cognitive limitations with rigorous mathematical security. A sequence of five common words is considerably simpler for human memory to retain than a dense string of arbitrary symbols. Simultaneously, the sheer length of the resulting phrase presents an overwhelming barrier to dictionary and brute-force cracking tools, prompting contemporary security standards to prioritise phrase length and genuine randomness over superficial character complexity.

3

Credential Stuffing and Automated Attacks

Among contemporary cyber threats, credential stuffing represents one of the most pervasive automated attack vectors targeting user authentication. This technique exploits widespread password reuse across distinct digital platforms. When a breach occurs on a single external service, threat actors obtain vast archives of email addresses and corresponding credentials. Rather than targeting the original breached entity, attackers deploy automated botnets to systematically test these stolen credential pairs against thousands of unrelated banking, retail, and corporate websites.

The efficacy of credential stuffing stems from human behavioural habits and the sheer scale of modern automation. Because individuals frequently use identical passwords across multiple personal and professional accounts, even low success rates yield substantial numbers of compromised profiles when millions of login attempts are executed daily. Furthermore, modern bot infrastructures rotate residential network addresses and mimic human browsing patterns to circumvent basic volumetric detection mechanisms.

To defend against credential stuffing, digital services must implement sophisticated, multi-layered defensive controls. Simple password strength requirements are ineffective, as the submitted credentials are fully valid. Instead, organisations rely on automated rate limiting, behavioural analysis, and threat intelligence feeds that cross-reference login attempts against known breach repositories. Additionally, secondary verification challenges are dynamically triggered when anomalous device characteristics or sudden geographic discrepancies are detected during the authentication handshake.

Want to answer the other 2?

Log in to practise Summarize Written Text in the BandLadder app: the full question bank, instant scoring the way Pearson marks it, and answer explanations.

Ready for the whole test?

Take a full PTE mock with every question type, the real timings and a score on Pearson's 10–90 scale the moment you finish.

Try a free PTE mock →

Keep practising

More Summarize Written Text sets

Practise every PTE question type

  • ✓Full question bank for every type
  • ✓Instant scoring, marked the way Pearson does
  • ✓BandLadder AI scoring for speaking and writing
Practise in the app

Free account · no card

© 2026 BandLadder. Written and checked by the BandLadder team. You may quote or cite this page with credit to BandLadder and a link to it; republishing it in full needs our written permission. Content use policy

Log in to practise all 3