Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CAS-005 Exam - Topic 2 Question 31 Discussion

A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:An administrator's account was hijacked and used on several Autonomous System Numbers within 30 minutes.All administrators use named accounts that require multifactor authentication.Single sign-on is used for all company applications.Which of the following should the security architect do to mitigate the issue?
B) Enable context-based authentication when network locations change on administrator login attempts.
A) Configure token theft detection on the single sign-on system with automatic account lockouts.
C) Decentralize administrator accounts and force unique passwords for each application.
D) Enforce biometric authentication requirements for the administrator's named accounts.

CompTIA CAS-005 Exam - Topic 2 Question 31 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 31
Topic #: 2
[All CAS-005 Questions]

A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:

An administrator's account was hijacked and used on several Autonomous System Numbers within 30 minutes.

All administrators use named accounts that require multifactor authentication.

Single sign-on is used for all company applications.Which of the following should the security architect do to mitigate the issue?

Show Suggested Answer Hide Answer
Suggested Answer: B

The hijacked administrator account was used across multiple ASNs (indicating different network locations) in a short time, despite MFA and SSO. This suggests a stolen session or token misuse. Let's analyze:

A . Token theft detection with lockouts:Useful for detecting stolen SSO tokens, but it's reactive and may not prevent initial misuse across networks.

B . Context-based authentication:This adds real-time checks (e.g., geolocation, IP changes) to verify login attempts. Given the rapid ASN changes, this proactively mitigates the issue by challenging suspicious logins, aligning with CAS-005's focus on adaptive security.

C . Decentralize accounts:This removes SSO, increasing complexity and weakening MFA enforcement, which isn't practical or secure.


Contribute your Thoughts:

0/2000 characters
Hayley
5 hours ago
I think option A is the best choice. Token theft detection is crucial.
upvoted 0 times
...
Suzi
5 days ago
I feel like A and B together would be ideal.
upvoted 0 times
...
Wei
11 days ago
B could prevent hijacking in the first place.
upvoted 0 times
...
Minna
16 days ago
Exactly, A covers immediate threats effectively.
upvoted 0 times
...
Louvenia
21 days ago
True, but we need strong measures after a breach.
upvoted 0 times
...
Suzi
26 days ago
D is interesting, but it might complicate access too much.
upvoted 0 times
...
Wei
1 month ago
C seems risky. Decentralizing could create more issues.
upvoted 0 times
...
Minna
1 month ago
I agree, but B could also help with location changes.
upvoted 0 times
...
Louvenia
1 month ago
I think option A is the best choice. Token theft detection is crucial.
upvoted 0 times
...
Pilar
2 months ago
D) would definitely add an extra layer of security!
upvoted 0 times
...
Mona
2 months ago
Wait, how did the hijacker bypass MFA in the first place?
upvoted 0 times
...
Simona
2 months ago
C) is risky, decentralizing could lead to more chaos.
upvoted 0 times
...
Jonelle
2 months ago
I disagree, B) would be more effective in preventing hijacks.
upvoted 0 times
...
Maurine
2 months ago
A) sounds like a solid choice for immediate action.
upvoted 0 times
...
Ryan
2 months ago
Biometric authentication seems like a strong option, but I’m not clear if it’s practical for all administrators in this scenario.
upvoted 0 times
...
Sueann
3 months ago
I practiced a similar question where decentralizing accounts was suggested, but I wonder if that would complicate management too much.
upvoted 0 times
...
Phil
3 months ago
Context-based authentication sounds familiar; I think it could help by adding another layer of security based on the admin's location.
upvoted 0 times
...
Avery
3 months ago
I remember studying about token theft detection, but I'm not sure if it would be effective in this case since MFA is already in place.
upvoted 0 times
...

Save Cancel