ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 235 - CS0-003 discussion

Report
Export

A security analyst received an alert regarding multiple successful MFA log-ins for a particular user When reviewing the authentication logs the analyst sees the following:

Which of the following are most likely occurring, based on the MFA logs? (Select two).

A.
Dictionary attack
Answers
A.
Dictionary attack
B.
Push phishing
Answers
B.
Push phishing
C.
impossible geo-velocity
Answers
C.
impossible geo-velocity
D.
Subscriber identity module swapping
Answers
D.
Subscriber identity module swapping
E.
Rogue access point
Answers
E.
Rogue access point
F.
Password spray
Answers
F.
Password spray
Suggested answer: B, C

Explanation:

C) Impossible geo-velocity: This is an event where a single user's account is accessed from different geographical locations within a timeframe that is impossible for normal human travel. In the log, we can see that the user 'jdoe' is accessing from the United States and then within a few minutes from Russia, which is practically impossible to achieve without the use of some form of automated system or if the account credentials are being used by different individuals in different locations.

B) Push phishing: This could also be an indication of push phishing, where the user is tricked into approving a multi-factor authentication request that they did not initiate. This is less clear from the logs directly, but it could be inferred if the user is receiving MFA requests that they are not initiating and are being approved without their genuine desire to access the resources.

asked 02/10/2024
Oliver Mark
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first