exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 386 discussion

Actual exam question from CompTIA's CS0-003
Question #: 386
Topic #: 1
[All CS0-003 Questions]

A security administrator has found indications of dictionary attacks against the company’s external-facing portal. Which of the following should be implemented to best mitigate the password attacks?

  • A. Multifactor authentication
  • B. Password complexity
  • C. Web application firewall
  • D. Lockout policy
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
52895e9
Highly Voted 3 months, 4 weeks ago
Selected Answer: B
Your first layer of protection against dictionary attacks would be password complexity. Second layer would be multifactor authentication.
upvoted 7 times
...
BlackSkullz
Most Recent 2 days, 14 hours ago
Selected Answer: D
Lockout policies are specifically created to counter dictionary attacks. It locks the account for a certain amount of time after so many failed attempts, which would make it extremely time consuming and impractical for the attacker to target. MFA and complex passwords are also good measures but they wouldn't directly address the constant bombardment of login attempts. A WAF might be of assistance as well but it's questionable since most brute force attacks come in the form of legitimate login attempts
upvoted 1 times
...
Susan4041
5 days, 21 hours ago
Selected Answer: A
B would not mitigate the issue only A
upvoted 1 times
...
NobleSub
1 month, 2 weeks ago
Selected Answer: B
I'm saying B. The questions states there are indicators of dictionary attacks. To best protect against dictionary attacks would be Password complexity.
upvoted 1 times
...
SAMIcho
2 months, 1 week ago
Selected Answer: D
The best option to mitigate dictionary attacks is: D. Lockout policy ✅
upvoted 2 times
...
0xdexter
2 months, 3 weeks ago
Selected Answer: D
The answer is D and here's why: even if you implemented complex passwords it could be leaked on the dark web, therefore it's not B. and its not A because MFA can be bypassed.
upvoted 2 times
...
Wolf541
2 months, 3 weeks ago
Selected Answer: A
I agree with speed I think the answer is A because even if they guess the password they would need another form of authentication to login to the account.
upvoted 1 times
...
Popeyes_Chicken
2 months, 4 weeks ago
Selected Answer: B
They're definitely looking for password complexity here with the key term dictionary attack. Dictionary attacks thrive off of weak passwords.
upvoted 3 times
...
speed69
3 months, 2 weeks ago
Selected Answer: A
its A, since the attacker would also need the other factor. Password complexity wouldn't fix the issue since its a dictionary attack. when you use complicated passwords people start to use the waterfall password, or other simple methods. Lockout policy would be good but the attacker could get lucky and still gain access within the lockout limit. MFA is the best solution compared to all the other options above.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago