[Governance, Risk, and Compliance (GRC)]
A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:
An administrator's account was hijacked and used on several Autonomous System Numbers within 30 minutes.
All administrators use named accounts that require multifactor authentication.
Single sign-on is used for all company applications.Which of the following should the security architect do to mitigate the issue?
Comprehensive and Detailed
The hijacked administrator account was used across multiple ASNs (indicating different network locations) in a short time, despite MFA and SSO. This suggests a stolen session or token misuse. Let's analyze:
A . Token theft detection with lockouts:Useful for detecting stolen SSO tokens, but it's reactive and may not prevent initial misuse across networks.
B . Context-based authentication:This adds real-time checks (e.g., geolocation, IP changes) to verify login attempts. Given the rapid ASN changes, this proactively mitigates the issue by challenging suspicious logins, aligning with CAS-005's focus on adaptive security.
C . Decentralize accounts:This removes SSO, increasing complexity and weakening MFA enforcement, which isn't practical or secure.
Ettie
8 months agoSylvia
9 months agoLuisa
9 months agoMiles
9 months agoPok
10 months agoKathrine
10 months agoShanice
10 months agoShaniqua
10 months agoChandra
10 months agoVallie
11 months agoClaudia
11 months agoShawn
11 months agoCharlie
11 months agoMelda
11 months agoTu
12 months agoValentin
12 months agoTu
12 months agoSamira
12 months agoBea
8 months agoIlene
8 months agoFrancis
9 months agoMozell
9 months agoAnglea
1 year agoFrederica
12 months ago