ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 313 - CS0-003 discussion

Report
Export

A high volume of failed RDP authentication attempts was logged on a critical server within a one-hour period. All of the attempts originated from the same remote IP address and made use of a single valid domain user account. Which of the following would be the most effective mitigating control to reduce the rate of success of this brute-force attack?

A.
Enabling a user account lockout after a limited number of failed attempts
Answers
A.
Enabling a user account lockout after a limited number of failed attempts
B.
Installing a third-party remote access tool and disabling RDP on all devices
Answers
B.
Installing a third-party remote access tool and disabling RDP on all devices
C.
Implementing a firewall block for the remote system's IP address
Answers
C.
Implementing a firewall block for the remote system's IP address
D.
Increasing the verbosity of log-on event auditing on all devices
Answers
D.
Increasing the verbosity of log-on event auditing on all devices
Suggested answer: A

Explanation:

Enabling a user account lockout policy is a security measure that can effectively mitigate brute-force attacks. After a predetermined number of consecutive failed login attempts, the account will be locked, preventing the attacker from continuing to try different password combinations. This control directly addresses the issue of multiple failed attempts from the same IP address using a single user account, making it the most effective among the options provided. Option B suggests replacing RDP with another remote access tool, which does not address the brute-force attempt but rather avoids the RDP protocol. Option C, implementing a firewall block, could be effective but does not prevent attacks from other IP addresses and may not be as immediate. Option D, increasing log verbosity, enhances monitoring but does not prevent the attack itself.

asked 02/10/2024
Oleksii Ivanov
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first