ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 51 - ECSS discussion

Report
Export

Robert, a security specialist, was appointed to strengthen the security of the organization's network. To prevent multiple login attempts from unknown sources, Robert implemented a security strategy of issuing alerts or warning messages when multiple failed login attempts are made.

Which of the following security risks is addressed by Robert to make attempted break-ins unsuccessful?

A.

Indefinite session timeout

Answers
A.

Indefinite session timeout

B.

Absence of account lockout for invalid session IDs

Answers
B.

Absence of account lockout for invalid session IDs

C.

Small session-ID generation

Answers
C.

Small session-ID generation

D.

Weak session-ID generation

Answers
D.

Weak session-ID generation

Suggested answer: B

Explanation:

Robert's strategy of issuing alerts or warning messages when multiple failed login attempts occur is aimed at addressing the risk ofabsence of account lockout for invalid session IDs.By locking out accounts temporarily after a certain number of failed login attempts, Robert prevents attackers from repeatedly guessing passwords or trying different session IDs to gain unauthorized access.Reference: EC-Council Certified Security Specialist (E|CSS) documents and study guide12.

asked 24/10/2024
Nelson Mira
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first