exam questions

Exam Lead Implementer All Questions

View all questions & answers for the Lead Implementer exam

Exam Lead Implementer topic 1 question 11 discussion

Actual exam question from PECB's Lead Implementer
Question #: 11
Topic #: 1
[All Lead Implementer Questions]

FinanceX, a well-known financial institution, uses an online banking platform that enables clients to easily and securely access their bank accounts. To log in, clients are required to enter the one-time authorization code sent to their smartphone. What can be concluded from this scenario?

  • A. FinanceX has implemented a security control that ensures the confidentiality of information
  • B. FinanceX has implemented an integrity control that avoids the involuntary corruption of data
  • C. FinanceX has incorrectly implemented a security control that could become a vulnerability
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Community vote distribution
A (75%)
C (25%)

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
AlphaFocus
2 weeks ago
Selected Answer: A
The Answer is A, it is a security control. and there are no further instructions regarding any prospective incidence. So We need to limit our response of choice to the question scope. not what we think might happen.
upvoted 1 times
...
usuari000
2 weeks, 6 days ago
Selected Answer: C
I am sorry but I do not agree with the proposed answer. Question does not mention there is another method of authentication, only a message delivered to the phone. Therefore, a bad actor with possession of the smartphone would be able to log into the account. This is a single method of authentication, just as weak as only using user and password. Additionally, it does not mention how the message is delivered to the smartphone. SIM cloning is a known attack against SMS OTPs, therefore I propose C to be the right answer.
upvoted 1 times
...
Acrisius
2 months, 2 weeks ago
Selected Answer: A
The answer here is A A. FinanceX has implemented a security control that ensures the confidentiality of information Technical control - Secure authentication (8.5) is a preventative control with Information security properties of #Confidentiality, #Integrity & #Availability Purpose to ensure a user or entity is securely authenticated when access to systems, applications and services is granted. B. FinanceX has implemented an integrity control that avoids the involuntary corruption of data Authentication has nothing to do with integrity of data C. FinanceX has incorrectly implemented a security control that could become a vulnerability The question makes no mention of incorrect implementation and so this is not the answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
AZ-801
Warsaw, 1 minute ago