ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 483 - CAS-004 discussion

Report
Export

A company has been the target of LDAP injections, as well as brute-force, whaling, and spear-phishing attacks. The company is concerned about ensuring continued system access. The company has already implemented a SSO system with strong passwords. Which of the following additional controls should the company deploy?

A.
Two-factor authentication
Answers
A.
Two-factor authentication
B.
Identity proofing
Answers
B.
Identity proofing
C.
Challenge questions
Answers
C.
Challenge questions
D.
Live identity verification
Answers
D.
Live identity verification
Suggested answer: A

Explanation:

While the company has implemented Single Sign-On (SSO) with strong passwords, additional security controls are required to mitigate attacks such as LDAP injections, brute-force, whaling, and spear-phishing. Two-factor authentication (2FA) provides an additional layer of security by requiring users to provide two different forms of authentication (e.g., a password and a security token or a biometric factor), reducing the likelihood of unauthorized access even if passwords are compromised. CASP+ emphasizes the importance of using multi-factor authentication mechanisms to strengthen access control and protect against such attacks.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Access Control and Multi-factor Authentication)

CompTIA CASP+ Study Guide: Implementing Two-Factor Authentication for System Access

asked 02/10/2024
Flora Hundal
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first