ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 550 - SY0-601 discussion

Report
Export

An attacker is attempting to harvest user credentials on a client's website. A security analyst notices multiple attempts of random usernames and passwords. When the analyst types in a random username and password, the logon screen displays the following message:

The username you entered does not exist.

Which of the following should the analyst recommend be enabled?

A.
Input validation
Answers
A.
Input validation
B.
Obfuscation
Answers
B.
Obfuscation
C.
Error handling
Answers
C.
Error handling
D.
Username lockout
Answers
D.
Username lockout
Suggested answer: D

Explanation:

Username lockout is a security feature that prevents an attacker from brute-forcing user credentials by locking out an account after a certain number of failed login attempts. This can prevent the attacker from harvesting user credentials on a client's website. The logon screen message that reveals the username does not exist is a security weakness that can help the attacker to guess valid usernames. A better message would be "Invalid username or password".

asked 02/10/2024
Pedro Perez
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first