ExamGecko
Question list
Search
Search

Question 47 - IT Risk Fundamentals discussion

Report
Export

An enterprise that uses a two-factor authentication login method for accessing sensitive data has implemented which type of control?

A.

Preventive

Answers
A.

Preventive

B.

Corrective

Answers
B.

Corrective

C.

Detective

Answers
C.

Detective

Suggested answer: A

Explanation:

An enterprise that uses a two-factor authentication login method for accessing sensitive data has implemented a preventive control. Here's why:

Preventive Control: This type of control is designed to prevent security incidents before they occur. Two-factor authentication (2FA) enhances security by requiring two forms of verification (e.g., a password and a mobile code) to access sensitive data. This prevents unauthorized access by ensuring that even if one authentication factor (like a password) is compromised, the second factor remains a barrier to entry.

Corrective Control: These controls come into play after an incident has occurred, aiming to correct or mitigate the impact. Examples include restoring data from backups or applying patches after a vulnerability is exploited. 2FA does not correct an incident but prevents it from happening.

Detective Control: These controls are designed to detect and alert about incidents when they happen. Examples include intrusion detection systems (IDS) and audit logs. 2FA is not about detection but about prevention.

Therefore, two-factor authentication is a preventive control.

asked 18/11/2024
David Kimovec
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first