Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil ECSS Exam - Topic 7 Question 123 Discussion

Robert, a security specialist, was appointed to strengthen the security of the organization's network. To prevent multiple login attempts from unknown sources, Robert implemented a security strategy of issuing alerts or warning messages when multiple failed login attempts are made.Which of the following security risks is addressed by Robert to make attempted break-ins unsuccessful?
B) Absence of account lockout for invalid session IDs
A) Indefinite session timeout
C) Small session-ID generation
D) Weak session-ID generation

Eccouncil ECSS Exam - Topic 7 Question 123 Discussion

Actual exam question for Eccouncil's ECSS exam
Question #: 123
Topic #: 7
[All ECSS Questions]

Robert, a security specialist, was appointed to strengthen the security of the organization's network. To prevent multiple login attempts from unknown sources, Robert implemented a security strategy of issuing alerts or warning messages when multiple failed login attempts are made.

Which of the following security risks is addressed by Robert to make attempted break-ins unsuccessful?

Show Suggested Answer Hide Answer
Suggested Answer: B

Robert's strategy of issuing alerts or warning messages when multiple failed login attempts occur is aimed at addressing the risk ofabsence of account lockout for invalid session IDs.By locking out accounts temporarily after a certain number of failed login attempts, Robert prevents attackers from repeatedly guessing passwords or trying different session IDs to gain unauthorized access.Reference: EC-Council Certified Security Specialist (E|CSS) documents and study guide12.


Contribute your Thoughts:

0/2000 characters
Dorethea
3 days ago
Agreed, but I wonder if it covers all possible threats.
upvoted 0 times
...
Dion
8 days ago
Definitely a good strategy, but what about session timeouts?
upvoted 0 times
...
Aja
13 days ago
Wait, are alerts really enough? Seems a bit basic.
upvoted 0 times
...
Jamie
18 days ago
I think this mainly addresses option B.
upvoted 0 times
...
Kenny
23 days ago
Sounds like a solid move to prevent brute force attacks!
upvoted 0 times
...
Theresia
29 days ago
I believe Robert's strategy is addressing the absence of account lockout, which is crucial for preventing brute-force attacks.
upvoted 0 times
...
Tricia
1 month ago
I’m a bit confused about the options. I thought weak session-ID generation was more about how IDs are created, not failed logins.
upvoted 0 times
...
In
1 month ago
This question feels similar to one we practiced on session management risks. I think it might relate to account lockout.
upvoted 0 times
...
Sylvie
1 month ago
I remember studying about account lockout mechanisms, but I'm not sure if that's the main focus here.
upvoted 0 times
...

Save Cancel